{"id":"JLSEC-2026-87","summary":"NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on...","details":"NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.","modified":"2026-07-25T18:24:54.327970126Z","published":"2026-04-13T13:20:05.063Z","upstream":["CVE-2025-43903","GHSA-4w9g-4h2x-7qxq","EUVD-2025-11892"],"database_specific":{"license":"CC-BY-4.0","sources":[{"imported":"2026-07-17T22:40:54.615Z","modified":"2026-06-17T09:24:42.673Z","published":"2025-04-18T21:15:44.673Z","url":"https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2025-43903","html_url":"https://nvd.nist.gov/vuln/detail/CVE-2025-43903","database_specific":{"status":"Analyzed"},"id":"CVE-2025-43903"},{"published":"2025-04-18T21:31:21Z","url":"https://api.github.com/advisories/GHSA-4w9g-4h2x-7qxq","html_url":"https://github.com/advisories/GHSA-4w9g-4h2x-7qxq","id":"GHSA-4w9g-4h2x-7qxq","imported":"2026-07-17T22:40:54.769Z","modified":"2025-04-18T21:31:28Z"},{"modified":"2025-04-21T02:51:02Z","published":"2025-04-18T00:00:00Z","url":"https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2025-11892","html_url":"https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-11892","id":"EUVD-2025-11892","imported":"2026-07-17T22:41:03.679Z"}]},"references":[{"type":"WEB","url":"https://github.com/advisories/GHSA-4w9g-4h2x-7qxq"},{"type":"WEB","url":"https://gitlab.freedesktop.org/poppler/poppler/-/commit/f1b9c830f145a0042e853d6462b2f9ca4016c669"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-43903"}],"affected":[{"package":{"name":"Poppler_jll","ecosystem":"Julia","purl":"pkg:julia/Poppler_jll?uuid=9c32591e-4766-534b-9725-b71a8799265b"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"25.10.0+0"}]}],"database_specific":{"source":"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-87.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"}]}