CVE-2026-3308 PUBLISHED

CVE-2026-3308

Assigner: certcc
Reserved: 26.02.2026 Published: 31.03.2026 Updated: 31.03.2026

An integer overflow vulnerability in 'pdf-image.c' in Artifex's MuPDF version 1.27.0 allows an attacker to maliciously craft a PDF that can trigger an integer overflow within the 'pdf_load_image_imp' function. This allows a heap out-of-bounds write that could be exploited for arbitrary code execution.

Product Status

Vendor Artifex Software Inc. *PyMuPDF*
Product MuPDF
Versions
  • affected from 0 to 1.27.0 (incl.)

References

Problem Types

  • CWE-190 Integer Overflow or Wraparound