Description
A flaw has been found in Artifex MuPDF up to b6d17493700c621c0e70036980a6ebd06d2202c9. Affected by this vulnerability is the function pdf_open_filter of the file pdf-stream.c of the component PDF Xref Loading. Executing a manipulation can lead to null pointer dereference. The attack can be launched remotely. The exploit has been published and may be used. This patch is called 3df1e30f9d7b77260e13bd0dbe1928ddeba8386e. Applying a patch is advised to resolve this issue.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote exploitation possible via null pointer dereference
Action: Patch immediately
AI Analysis

Impact

The flaw lies in the pdf_open_filter function of MuPDF’s PDF Xref Loading component. Processing a specially crafted PDF can cause a null pointer dereference, which may lead to a crash or other unintended behavior. The description states that the attack can be launched remotely and that published exploits exist. Delivering a malformed PDF can trigger the dereference, potentially compromising the integrity or stability of the application using the library.

Affected Systems

All installations of Artifex MuPDF before commit 3df1e30f9d7b77260e13bd0dbe1928ddeba8386e are affected. This includes every application or service that links against the MuPDF library, such as PDF viewers, document converters, or other software components that embed the library.

Risk and Exploitability

The CVSS score of 5.3 classifies this vulnerability as moderate. With an EPSS score of less than 1%, exploitation attempts are currently rare and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, the attack can be performed remotely by providing a malicious PDF, and published exploits are already available, so the risk remains non‑negligible for systems that consume untrusted documents.

Generated by OpenCVE AI on September 18, 2026 at 07:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the patch commit 3df1e30f9d7b77260e13bd0dbe1928ddeba8386e to the MuPDF source or upgrade to a release that includes this fix.
  • Replace any bundled MuPDF instances in applications, services, containers, or firmware with the patched version across all deployments, coordinating updates with development and operations teams.
  • Limit access to PDF rendering for untrusted documents by sandboxing the rendering process or restricting file intake until the environment is fully patched, and monitor for anomalous PDF handling.

Generated by OpenCVE AI on September 18, 2026 at 07:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Artifex MuPDF up to b6d17493700c621c0e70036980a6ebd06d2202c9. Affected by this vulnerability is the function pdf_open_filter of the file pdf-stream.c of the component PDF Xref Loading. Executing a manipulation can lead to null pointer dereference. The attack can be launched remotely. The exploit has been published and may be used. This patch is called 3df1e30f9d7b77260e13bd0dbe1928ddeba8386e. Applying a patch is advised to resolve this issue.
Title Artifex MuPDF PDF Xref Loading pdf-stream.c pdf_open_filter null pointer dereference
First Time appeared Artifex
Artifex mupdf
Weaknesses CWE-404
CWE-476
CPEs cpe:2.3:a:artifex:mupdf:*:*:*:*:*:*:*:*
Vendors & Products Artifex
Artifex mupdf
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-18T18:14:41.275Z

Reserved: 2026-09-16T09:32:58.686Z

Link: CVE-2026-92413

cve-icon Vulnrichment

Updated: 2026-09-18T18:14:33.444Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T18:17:20.617

Modified: 2026-09-18T19:17:16.900

Link: CVE-2026-92413

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:30:05Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release

  • CWE-476

    NULL Pointer Dereference