---
id: CVE-2026-92413
title: >-
  A flaw has been found in Artifex MuPDF up to
  b6d17493700c621c0e70036980a6ebd06d2202c9
summary: >-
  A flaw has been found in Artifex MuPDF up to
  b6d17493700c621c0e70036980a6ebd06d2202c9. Affected by this vulnerability is
  the function pdf_open_filter of the file pdf-stream.c of the component PDF
  Xref Loading. Executing a manipulation ca…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L'
cwe:
  - CWE-404
  - CWE-476
vendor: Artifex
product: MuPDF
affected:
  - MuPDF b6d17493700c621c0e70036980a6ebd06d2202c9
published: '2026-09-16'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:17:16.900'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92413'
references:
  - url: 'https://artifex.com/'
    label: cna@vuldb.com
  - url: 'https://bugs.ghostscript.com/attachment.cgi?id=28434'
    label: cna@vuldb.com
  - url: 'https://bugs.ghostscript.com/show_bug.cgi?id=709610'
    label: cna@vuldb.com
  - url: >-
      https://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=3df1e30f9d7b77260e13bd0dbe1928ddeba8386e
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-92413'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/940975'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/405593'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/405593/cti'
    label: cna@vuldb.com
  - url: 'https://bugs.ghostscript.com/show_bug.cgi?id=709610'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-92413.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-92413'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-92413'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
  - exploit-available
epss: 0.00594
epssPercentile: 0.46046
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-18T18:14:08.965941Z'
ingestedAt: '2026-09-16T18:01:17.460Z'
---

## Overview

A flaw has been found in Artifex MuPDF up to b6d17493700c621c0e70036980a6ebd06d2202c9. Affected by this vulnerability is the function pdf_open_filter of the file pdf-stream.c of the component PDF Xref Loading. Executing a manipulation can lead to null pointer dereference. The attack can be launched remotely. The exploit has been published and may be used. This patch is called 3df1e30f9d7b77260e13bd0dbe1928ddeba8386e. Applying a patch is advised to resolve this issue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-92413.json)
