---
id: CVE-2026-3308
title: >-
  An integer overflow vulnerability in 'pdf-image.c' in Artifex's MuPDF version
  1.27.0 allows an attacker to maliciously craft a PDF that can trigger an
  integer overflow within the 'pdf_load_image_imp' function
summary: >-
  An integer overflow vulnerability in 'pdf-image.c' in Artifex's MuPDF version
  1.27.0 allows an attacker to maliciously craft a PDF that can trigger an
  integer overflow within the 'pdf_load_image_imp' function. This allows a heap
  out-of-b…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-190
published: '2026-03-31'
updated: '2026-07-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-3308'
references:
  - url: >-
      https://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=a26f0142e7d390d4a82c6e5ae0e312e07cc4ec85
    label: cret@cert.org
  - url: 'https://github.com/ArtifexSoftware/mupdf'
    label: cret@cert.org
  - url: >-
      https://github.com/ArtifexSoftware/mupdf/commit/a26f0142e7d390d4a82c6e5ae0e312e07cc4ec85
    label: cret@cert.org
  - url: 'https://lists.debian.org/debian-lts-announce/2026/04/msg00020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.kb.cert.org/vuls/id/951662'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00213
epssPercentile: 0.11951
ingestedAt: '2026-07-25T10:53:53.729Z'
---

## Overview

An integer overflow vulnerability in 'pdf-image.c' in Artifex's MuPDF version 1.27.0 allows an attacker to maliciously craft a PDF that can trigger an integer overflow within the 'pdf_load_image_imp' function. This allows a heap out-of-bounds write that could be exploited for arbitrary code execution.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
