PT-2026-93875 · Artifex+1 · Mupdf

·

CVE-2026-92413

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Artifex MuPDF versions prior to 3df1e30f9d7b77260e13bd0dbe1928ddeba8386e
Description A remote flaw exists in the PDF Xref Loading component within the pdf open filter() function of the pdf-stream.c file. A manipulation of this function can lead to a null pointer dereference, which occurs when a program attempts to read or write to a memory address that is null, typically causing the application to crash.
Recommendations Apply patch 3df1e30f9d7b77260e13bd0dbe1928ddeba8386e. As a temporary workaround, restrict the processing of untrusted PDF files to minimize the risk of exploitation.

Exploit

Fix

NULL Pointer Dereference

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92413

Affected Products

Mupdf