
Cloud Vulnerability DB
A community-led vulnerabilities database
Cairo through version 1.18.4, as used in Poppler through 25.08.0, contains a vulnerability related to an assertion failure in the cairoftunscaledfont_fini function within cairo-ft-font.c. The vulnerability was discovered and disclosed on August 4, 2025 (NVD).
The vulnerability is characterized by an 'unscaled->face == NULL' assertion failure that occurs in the cairoftunscaledfont_fini function within cairo-ft-font.c. The issue has been assigned a CVSS v3.1 base score of 5.5 (Medium) with vector string CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N, indicating local access is required and user interaction is necessary for exploitation (Snyk).
The vulnerability primarily affects the confidentiality aspect of the system, with a High impact rating for confidentiality but no impact on integrity or availability. When exploited, it could potentially allow attackers to access sensitive PDF content through memory exposure (NVD).
The vulnerability has been acknowledged by the vendor (freedesktop, maintainer of Poppler) and has been fixed. The fix has been committed in their official repository through merge request 621 in the Cairo repository and issue 1591 in the Poppler repository (GitHub).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."