logo

The MuPDF Vulnerability Turning “Safe” PDFs into System Hijackers

ID: 57595f0b-2d8f-5ab0-b158-8df3858e8fbc

STIX ID: report--57595f0b-2d8f-5ab0-b158-8df3858e8fbc

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2026-04-03

Date Updated: 2026-04-23

Author: Ddos

...
...

A high-severity integer overflow (CVE-2026-3308, CVSS 7.8) was discovered in Artifex MuPDF's image processing (pdf-image.c) where stride/size checks use SIZE_MAX instead of INT_MAX, enabling a heap out-of-bounds write and possible arbitrary code execution when rendering crafted PDFs; the flaw affects MuPDF ≤1.27.0, the vendor was reportedly unreachable, a community pull request exists but no official vendor patch has been released, and mitigations include not processing untrusted PDFs, sandboxing rendering, and disabling automatic rendering.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.