CVE-2025-50422 affects Cairo through version 1.18.4, as used in Poppler through version 25.08.0. The vulnerability involves failure of the "unscaled->face == NULL" assertion in _cairo_ft_unscaled_font_fini, a function in Cairo's FreeType font backend. Triggering the assertion can terminate the application using the affected library.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a proof-of-concept (POC) exploit for a vulnerability in Poppler's pdftocairo utility (prior to version 25.04.0). The vulnerability arises from improper clearing of heap memory containing PDF object streams when pdftocairo calls cairo_debug_reset_static_data() on exit. The POC is provided as a crafted PDF file ('poppler-pdftocairo-poc') that, when processed by a vulnerable version of pdftocairo, leaves sensitive PDF content in process memory. An attacker with local access can then dump the process memory and recover clear-text PDF data. The repository also includes a README describing the vulnerability, its impact, and links to the vendor's patch and issue tracker. There are no network endpoints or remote attack vectors; exploitation requires local access and interaction with the vulnerable utility.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An assertion-failure vulnerability in Cairo's FreeType font cleanup code, affecting Cairo through 1.18.4 as used in Poppler through 25.08.0. The reported CVSS v3 score is 2.9, indicating a low availability impact with local access and high attack complexity. The recommended fix is updating Cairo and related packages to Echo version 1.18.4-1+e1 or later.
A historical Poppler/Cairo-path vulnerability mentioned to illustrate broader backend vulnerability history.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.