CVE Tools

Mupdf

70 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Mupdf, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Mupdf CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Mupdf CVEs per month
MonthCVEs
2024-100
2024-110
2024-121
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-081
2025-091
2025-100
2025-110
2025-120
2026-010
2026-022
2026-031
2026-042
2026-050
2026-061
2026-070
2026-080
2026-091

Severity

How the 70 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical34%
  • High2941%
  • Medium3651%
  • Low23%

Latest CVEs

The 15 most recently published vulnerabilities affecting Mupdf.

  1. CVE-2026-92413Artifex MuPDF PDF Xref Loading pdf-stream.c pdf_open_filter null pointer dereference4.3
  2. CVE-2025-71382MuPDF < 1.27.0-rc1 Stack Exhaustion DoS via EPUB CSS Rendering6.5
  3. CVE-2026-7233Artifex MuPDF CFF Index subset-cff.c fz_subset_cff_for_gids out-of-bounds3.3
  4. CVE-2026-40505MuPDF < 1.27 mutool ANSI Injection via Metadata3.3
  5. CVE-2026-3308CVE-2026-33087.8
  6. CVE-2025-15569Artifex MuPDF win_main.c get_system_dpi uncontrolled search path7.0
  7. CVE-2026-25556MuPDF 1.23.0 through 1.27.0 Barcode Decoding Double Free7.5
  8. CVE-2025-55780A null pointer dereference occurs in the function break_word_for_overflow_wrap() in MuPDF 1.26.4 when rendering a malformed EPUB document. Specifically, the function calls fz_html_split_flow() to s...7.5
  9. CVE-2025-46206An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service via an infinite recursion in the `mutool clean` utility. When processing a crafted PDF file containing...6.5
  10. CVE-2024-46657Artifex Software mupdf v1.24.9 was discovered to contain a segmentation fault via the component /tools/pdfextract.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a cra...5.5
  11. CVE-2024-24258freeglut 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddSubMenu function.7.5
  12. CVE-2024-24259freeglut through 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddMenuEntry function.7.5
  13. CVE-2023-51104A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in function pnm_binary_read_image() of load-pnm.c when span equals zero.7.5
  14. CVE-2023-51105A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in function bmp_decompress_rle4() of load-bmp.c.7.5
  15. CVE-2023-51106A floating point exception (divide-by-zero) vulnerability was discovered in mupdf 1.23.4 in function pnm_binary_read_image() of load-pnm.c when fz_colorspace_n returns zero.7.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store