rootpwn

medium · CVSS v3 4.3 · CVSS v4 5.3

CVE-2026-92413

A remote null‑pointer dereference flaw exists in Artifex MuPDF’s PDF Xref loading routine. The bug can crash the application when processing

Overview

A remote null‑pointer dereference flaw exists in Artifex MuPDF’s PDF Xref loading routine. The bug can crash the application when processing a crafted PDF, leading to a denial‑of‑service condition.

Description

A flaw has been found in Artifex MuPDF up to b6d17493700c621c0e70036980a6ebd06d2202c9. Affected by this vulnerability is the function pdf_open_filter of the file pdf-stream.c of the component PDF Xref Loading. Executing a manipulation can lead to null pointer dereference. The attack can be launched remotely. The exploit has been published and may be used. This patch is called 3df1e30f9d7b77260e13bd0dbe1928ddeba8386e. Applying a patch is advised to resolve this issue.

Impact

Availability: The vulnerability can cause MuPDF to crash, interrupting legitimate PDF processing and potentially disrupting services that rely on the viewer or renderer. No confirmed confidentiality or integrity impact has been reported.

Remediation

Upgrade MuPDF to a version that includes commit 3df1e30f9d7b77260e13bd0dbe1928ddeba8386e or later. If an update is not immediately possible, restrict access to untrusted PDF inputs, monitor for crashes, and apply any vendor‑issued runtime mitigations.

Risk context

The CVSS v3 score is 4.3 (medium) and CVSS v4 is 5.3, indicating a moderate impact. No EPSS data is available, so the likelihood of exploitation is unknown, but the published exploit suggests the risk is real. Prompt patching is recommended.

Affected products

  • Artifex MuPDF

Scores

Severity
medium
CVSS v2
5
CVSS v3
4.3
CVSS v4
5.3
EPSS

MuPDF PDF NullPointer Remote DenialOfService Patch MediumSeverity

← All CVEs