Skip to main content
Vulnerability Database/CVE-2026-92413

CVE-2026-92413: Artifex MuPDF Use-After-Free Vulnerability

CVE-2026-92413 is a use-after-free flaw in Artifex MuPDF that can lead to null pointer dereference attacks. This vulnerability affects PDF Xref loading and can be exploited remotely. This article covers technical details, affected versions, security impact, and available patches.

Published:

CVE-2026-92413 Overview

CVE-2026-92413 is a null pointer dereference vulnerability in Artifex MuPDF, a lightweight PDF, XPS, and e-book viewer. The flaw affects the pdf_open_filter function in pdf-stream.c, part of the PDF Xref Loading component. Processing a crafted PDF document can trigger the dereference and crash the application. The issue impacts versions up to commit b6d17493700c621c0e70036980a6ebd06d2202c9. A public exploit exists, though impact is limited to availability. The upstream patch is tracked as commit 3df1e30f9d7b77260e13bd0dbe1928ddeba8386e.

Critical Impact

Remote attackers can crash MuPDF-based applications by inducing a user to open a malicious PDF, producing a denial-of-service condition against the viewer process.

Affected Products

  • Artifex MuPDF up to commit b6d17493700c621c0e70036980a6ebd06d2202c9
  • The pdf_open_filter function in pdf-stream.c
  • PDF Xref Loading component of MuPDF

Discovery Timeline

  • 2026-09-16 - CVE-2026-92413 published to the National Vulnerability Database (NVD)
  • 2026-09-16 - Last updated in NVD database

Technical Details for CVE-2026-92413

Vulnerability Analysis

The vulnerability resides in pdf_open_filter, a function inside pdf-stream.c responsible for opening filtered PDF streams during cross-reference (Xref) table loading. When MuPDF parses a malformed PDF, execution reaches a code path where a pointer expected to reference a valid PDF object is NULL. Dereferencing that pointer terminates the process. This class of defect is categorized under CWE-404: Improper Resource Shutdown or Release, reflecting the incomplete state handling that leads to the crash.

The attack is network-reachable in the sense that the malicious PDF can be delivered over any transport such as email, web download, or file share. User interaction is required to open the document. Confidentiality and integrity are not impacted; only availability of the viewer process is affected.

Root Cause

The root cause is missing validation of an object pointer inside pdf_open_filter during Xref loading. When the cross-reference stream references an object that resolves to NULL, MuPDF proceeds to access fields on the null pointer instead of returning an error. The upstream patch 3df1e30f9d7b77260e13bd0dbe1928ddeba8386e addresses this by adding the missing guard on the object pointer before use.

Attack Vector

An attacker crafts a PDF whose Xref table triggers the vulnerable path in pdf_open_filter. The attacker delivers the file to a target using MuPDF or an application that embeds MuPDF as a rendering library. Opening the file crashes the process. The public exploit demonstrates the crash; no code execution primitive is documented. See the Ghostscript bug report and the associated proof-of-concept attachment for reproduction details.

No verified exploitation code is reproduced here. Refer to the upstream MuPDF commit 3df1e30f for the exact source-level fix.

Detection Methods for CVE-2026-92413

Indicators of Compromise

  • Unexpected termination of MuPDF binaries such as mupdf, mutool, or applications embedding libmupdf shortly after opening a PDF
  • Segmentation fault entries in system logs or crash dumps referencing pdf_open_filter or pdf-stream.c
  • PDF files with malformed Xref streams delivered through email attachments or web downloads

Detection Strategies

  • Inspect PDF documents for structurally invalid Xref tables before rendering, using PDF linters or sanitizers
  • Correlate process crash telemetry with recent PDF open events to identify targeted delivery attempts
  • Hash and track known malicious PDF samples referenced in the VulDB entry for CVE-2026-92413

Monitoring Recommendations

  • Monitor endpoint telemetry for repeated crashes of MuPDF-derived processes across the fleet
  • Alert on PDF files arriving from untrusted sources that immediately cause a viewer to exit abnormally
  • Track deployment inventory for applications embedding MuPDF to scope patch coverage

How to Mitigate CVE-2026-92413

Immediate Actions Required

  • Apply the upstream MuPDF patch identified by commit 3df1e30f9d7b77260e13bd0dbe1928ddeba8386e to affected builds
  • Rebuild and redistribute downstream applications that statically link libmupdf
  • Restrict opening of PDF files from untrusted sources until patched builds are deployed

Patch Information

The fix is available in the MuPDF commit 3df1e30f. Organizations that consume MuPDF as a library should pull the patched source from the upstream repository and rebuild. Refer to the Artifex official website for release channel information.

Workarounds

  • Sandbox MuPDF-based viewers so a crash does not propagate to the parent application or host
  • Preprocess incoming PDFs through a validating parser that rejects malformed Xref structures
  • Disable automatic PDF preview in mail clients and file managers that rely on MuPDF until patched
bash
# Build MuPDF from upstream with the fix applied
git clone --recursive https://git.ghostscript.com/mupdf.git
cd mupdf
git checkout 3df1e30f9d7b77260e13bd0dbe1928ddeba8386e
make HAVE_X11=no HAVE_GLUT=no
sudo make install

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.