Description
A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gids of the file subset-cff.c of the component CFF Index Handler. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through a bug report but has not responded yet.
Published: 2026-04-28
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local out-of-bounds read exposing memory contents
Action: Check Update
AI Analysis

Impact

The vulnerability in Artifex MuPDF up to version 1.28.0 stems from the fz_subset_cff_for_gids function in subset-cff.c, which performs an out-of-bounds read when processing certain PDF documents. This flaw can leak internal memory data and is classified as a buffer over-read (CWE-119) and an out-of-bounds read (CWE-125). The weakness potentially allows a local attacker to read unintended data, but it does not provide a remote code execution path.

Affected Systems

Artifex MuPDF, previous to 1.28.0. No other vendors or product variants are mentioned in the advisory, and the flaw is reported only in the subset-cff.c component of the CFF Index Handler.

Risk and Exploitability

The CVSS score of 4.8 indicates moderate severity, and the EPSS score is unavailable, suggesting limited exploitation probability. The flaw requires local execution of the vulnerable binary. The public disclosure indicates the existence of an exploit, but it is confined to users with local access, and it has not been featured in the CISA KEV catalog.

Generated by OpenCVE AI on April 28, 2026 at 12:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest MuPDF release that contains the CFF Index handler fix once it becomes available.
  • Restrict local execution of MuPDF to trusted users and run the process with least privilege.
  • If a patch is not yet available, consider disabling the CFF Index handler or switching to an alternative PDF viewer that does not contain the vulnerability.

Generated by OpenCVE AI on April 28, 2026 at 12:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Apr 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Apr 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Low


Tue, 28 Apr 2026 06:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gids of the file subset-cff.c of the component CFF Index Handler. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through a bug report but has not responded yet.
Title Artifex MuPDF CFF Index subset-cff.c fz_subset_cff_for_gids out-of-bounds
First Time appeared Artifex
Artifex mupdf
Weaknesses CWE-119
CWE-125
CPEs cpe:2.3:a:artifex:mupdf:*:*:*:*:*:*:*:*
Vendors & Products Artifex
Artifex mupdf
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-05T20:23:51.185Z

Reserved: 2026-04-27T17:00:07.970Z

Link: CVE-2026-7233

cve-icon Vulnrichment

Updated: 2026-04-29T15:14:50.739Z

cve-icon NVD

Status : Modified

Published: 2026-04-28T07:16:04.067

Modified: 2026-05-05T21:16:23.940

Link: CVE-2026-7233

cve-icon Redhat

Severity : Low

Publid Date: 2026-04-28T06:00:18Z

Links: CVE-2026-7233 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T12:30:31Z

Weaknesses