Artifex MuPDF CFF Index subset-cff.c fz_subset_cff_for_gids out-of-bounds
Published Apr 28, 2026
4.8
MEDIUMCVSS 4.0
EPSS 0.19%
Description
A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gids of the file subset-cff.c of the component CFF Index Handler. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through a bug report but has not responded yet.
Affected products
-
- Version 1.0StatusaffectedConstraints-
- Version 1.1StatusaffectedConstraints-
- Version 1.10StatusaffectedConstraints-
- Version 1.11StatusaffectedConstraints-
- Version 1.12StatusaffectedConstraints-
- Version 1.13StatusaffectedConstraints-
- Version 1.14StatusaffectedConstraints-
- Version 1.15StatusaffectedConstraints-
- Version 1.16StatusaffectedConstraints-
- Version 1.17StatusaffectedConstraints-
- Version 1.18StatusaffectedConstraints-
- Version 1.19StatusaffectedConstraints-
- Version 1.2StatusaffectedConstraints-
- Version 1.20StatusaffectedConstraints-
- Version 1.21StatusaffectedConstraints-
- Version 1.22StatusaffectedConstraints-
- Version 1.23StatusaffectedConstraints-
- Version 1.24StatusaffectedConstraints-
- Version 1.25StatusaffectedConstraints-
- Version 1.26StatusaffectedConstraints-
- Version 1.27StatusaffectedConstraints-
- Version 1.28.0StatusaffectedConstraints-
- Version 1.3StatusaffectedConstraints-
- Version 1.4StatusaffectedConstraints-
- Version 1.5StatusaffectedConstraints-
- Version 1.6StatusaffectedConstraints-
- Version 1.7StatusaffectedConstraints-
- Version 1.8StatusaffectedConstraints-
- Version 1.9StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Artifex | MuPDF | n/a |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability is rated as Low impact. The out-of-bounds read in Artifex MuPDF's CFF Index Handler requires local user access to exploit, limiting its potential for widespread impact on Red Hat systems. Successful exploitation could lead to information disclosure from memory.
Red Hat mitigation
Users should avoid opening untrusted or malicious PDF documents with applications that utilize the MuPDF library. If the `mupdf` package is not essential for system operation, consider removing it to eliminate the attack surface.
Metrics
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
1 other source (NVD) ▾
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
2 other sources (Red Hat, CVE.org) ▾
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R
AV:L/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR
1 other source (NVD) ▾
AV:L/AC:L/Au:S/C:P/I:N/A:N
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Apr 29, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
Apr–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.19% (0.00194) | 8.23th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.24% (0.00238) | 14.54th | v5 (v2026.06.15) |
| Apr 28, 2026 | 0.01% (0.00012) | 1.81th | v4 (v2025.03.14) |
References (10)
- https://access.redhat.com/security/cve/CVE-2026-7233 Vendor Advisory
- https://artifex.com/ product
- https://bugs.ghostscript.com/show_bug.cgi?id=709328 exploitissue-trackingMitigationThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2463367 Issue Tracking
- https://github.com/biniamf/pocs/tree/main/mupdf-cff-indexload-oobread exploit
- https://nvd.nist.gov/vuln/detail/CVE-2026-7233
- https://vuldb.com/submit/802590 exploitthird-party-advisoryMitigationThird Party AdvisoryVDB Entry
- https://vuldb.com/vuln/359840 vdb-entrytechnical-descriptionExploitMitigationThird Party AdvisoryVDB Entry
- https://vuldb.com/vuln/359840/cti signaturepermissions-requiredPermissions RequiredVDB Entry
- https://www.cve.org/CVERecord?id=CVE-2026-7233
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-7233 | Vendor Advisory | |
| https://artifex.com/ | product | |
| https://bugs.ghostscript.com/show_bug.cgi?id=709328 | exploitissue-trackingMitigationThird Party Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2463367 | Issue Tracking | |
| https://github.com/biniamf/pocs/tree/main/mupdf-cff-indexload-oobread | exploit | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-7233 | ||
| https://vuldb.com/submit/802590 | exploitthird-party-advisoryMitigationThird Party AdvisoryVDB Entry | |
| https://vuldb.com/vuln/359840 | vdb-entrytechnical-descriptionExploitMitigationThird Party AdvisoryVDB Entry | |
| https://vuldb.com/vuln/359840/cti | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://www.cve.org/CVERecord?id=CVE-2026-7233 |
Change history (0)
No recorded changes yet.