CVE-2026-3308
Artifex Software Inc. *PyMuPDF* MuPDF
An integer overflow vulnerability in 'pdf-image.c' in Artifex's MuPDF version 1.27.0 allows an attacker to maliciously craft a PDF that can trigger an integer overflow within the 'pdf_load_image_imp' function. This allows a heap out-of-bounds write that could be exploited for arbitrary code execution.
- CVSS
- 7.8
- EPSS
- 0.21% 11.7% percentile
- CISA KEV
- Not listed
- Published
- 2026.03.31