CVE-2026-3308 identifies a high-severity integer overflow vulnerability in Artifex's MuPDF version 1.27.0, specifically within the 'pdf-image.c' file. This flaw, rated 7.8 CVSS, allows an attacker to trigger a heap out-of-bounds write and achieve arbitrary code execution by convincing a user to open a maliciously crafted PDF document. Although user interaction is required and no public exploit code or active exploitation has been observed, the vulnerability is on the Hot List and has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 1.27.0CPE match | cpe:2.3:a:artifex:mupdf:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.