๐Ÿ” CVE Alert

CVE-2026-92413

MEDIUM 4.3

Artifex MuPDF PDF Xref Loading pdf-stream.c pdf_open_filter null pointer dereference

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

A flaw has been found in Artifex MuPDF up to b6d17493700c621c0e70036980a6ebd06d2202c9. Affected by this vulnerability is the function pdf_open_filter of the file pdf-stream.c of the component PDF Xref Loading. Executing a manipulation can lead to null pointer dereference. The attack can be launched remotely. The exploit has been published and may be used. This patch is called 3df1e30f9d7b77260e13bd0dbe1928ddeba8386e. Applying a patch is advised to resolve this issue.

CWE CWE-476 CWE-404
Vendor artifex
Product mupdf
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for artifex mupdf

Be the first to know when new medium vulnerabilities affecting artifex mupdf are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Artifex / MuPDF
b6d17493700c621c0e70036980a6ebd06d2202c9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/405593 vuldb.com: https://vuldb.com/vuln/405593/cti vuldb.com: https://vuldb.com/cve/CVE-2026-92413 vuldb.com: https://vuldb.com/submit/940975 bugs.ghostscript.com: https://bugs.ghostscript.com/show_bug.cgi?id=709610 bugs.ghostscript.com: https://bugs.ghostscript.com/attachment.cgi?id=28434 cgit.ghostscript.com: https://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=3df1e30f9d7b77260e13bd0dbe1928ddeba8386e artifex.com: https://artifex.com/

Credits

๐Ÿ” fczhang (VulDB User)