CVE-2026-25556Patch(artifex / mupdf)

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch artifex mupdf systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

MuPDF versions 1.23.0 through 1.27.0 contain a double-free vulnerability in fz_fill_pixmap_from_display_list() when an exception occurs during display list rendering. The function accepts a caller-owned fz_pixmap pointer but incorrectly drops the pixmap in its error handling path before rethrowing the exception. Callers (including the barcode decoding path in fz_decode_barcode_from_display_list) also drop the same pixmap in cleanup, resulting in a double-free that can corrupt the heap and crash the process. This issue affects applications that enable and use MuPDF barcode decoding and can be triggered by processing crafted input that causes a rendering-time error while decoding barcodes.

0.5/ 10 priority

Sources & remediation

Other references
Weakness type (CWE)
CWE-415

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mupdf

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-02-23)
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
mupdf

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-02-06: 1Mentions · 2026-02-22: 1Mentions · 2026-02-23: 3Patch / Workaround · 2026-02-23: 3Technical Details · 2026-02-06: 1Technical Details · 2026-02-22: 1Technical Details · 2026-02-23: 302-0602-2202-23
Signal classification2 categories
Patch
360.0%
Disclosure
240.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-061
Disclosure1
2026-02-221
Disclosure1
2026-02-233
Patch3
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-25556 MuPDF versions 1.23.0 through 1.27.0 contain a double-free vulnerability in fz_fill_pixmap_from_display_list() when an exception occurs during display list rendering.… https://www.cve.org/CVERecord?id=CVE-2026-25556

    Post summary

    The text announces a double‑free vulnerability in MuPDF 1.23.0 through 1.27.0, affecting the fz_fill_pixmap_from_display_list() function during display list rendering.

    00010184
    56.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    #Fedora 43: MuPDF 1.27.1 is out with a critical fix for CVE-2026-25556 (double-free in barcode decoding). Affects zathura-pdf-mupdf & PyMuPDF. Don't let a malicious PDF crash your heap. Read more: 👉https://tinyurl.com/3fkezbf9 #Security https://t.co/vAT7V32yBp

    Post summary

    The tweet announces that Fedora 43 includes a critical patch for CVE‑2026‑25556, a double‑free bug in MuPDF’s barcode decoding, and urges users to update to MuPDF 1.27.1.

    0000092
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Critical #Security advisory for the Fedora community: CVE-2026-25556 is a DoS vulnerability in PyMuPDF that can be triggered via crafted barcode decoding. If you're running #Fedora 43, the path to mitigation is upgrading to mupdf 1.27.1. Read more: 👉https://tinyurl.com/39bk5rw7 https://t.co/rtNJXtAZTf

    Post summary

    Fedora advisory warns of CVE-2026-25556, a DoS flaw in PyMuPDF triggered by crafted barcodes, and recommends upgrading to mupdf 1.27.1 to mitigate.

    0000077
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Critical security patch for #Fedora 43: MuPDF 1.27.1 is out. This update addresses CVE-2026-25556, a denial-of-service vulnerability triggered by malicious files during barcode decoding. Read more: 👉 https://tinyurl.com/2neuuw7p #Security https://t.co/QKZ2XQKvGn

    Post summary

    Fedora 43 users should update MuPDF to version 1.27.1 to mitigate CVE-2026-25556, a denial‑of‑service vulnerability triggered by malicious barcode files.

    0000065
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    Critical MuPDF vulnerability (CVE-2026-25556) lands for #Fedora 42. This isn't just a viewer issue—it's a DoS risk in a core parsing library. Read more: 👉 https://tinyurl.com/tnrw9wpn #Security https://t.co/ajllrI0W7h

    Post summary

    A critical DoS vulnerability in MuPDF (CVE-2026-25556) affecting Fedora 42 has been disclosed, emphasizing its impact on a core parsing library.

    0000057
    1.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appartifexmupdf---

Explore more