CVE-2026-3308Disclosure

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An integer overflow vulnerability in 'pdf-image.c' in Artifex's MuPDF version 1.27.0 allows an attacker to maliciously craft a PDF that can trigger an integer overflow within the 'pdf_load_image_imp' function. This allows a heap out-of-bounds write that could be exploited for arbitrary code execution.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-07); latest day: 1
  • 5 total mentions across 4 days

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-03-31: 1Mentions · 2026-04-03: 1Mentions · 2026-04-07: 2Mentions · 2026-04-21: 1Patch / Workaround · 2026-04-03: 1Patch / Workaround · 2026-04-07: 1Patch / Workaround · 2026-04-21: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-03: 1Technical Details · 2026-04-07: 2Technical Details · 2026-04-21: 103-3104-0304-0704-21
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-311
Disclosure1
2026-04-031
Disclosure1
2026-04-072
Disclosure2
2026-04-211
Patch1
Full discourse5 posts
  • Gray Hats@the_yellow_fall
    Disclosure

    Artifex MuPDF faces a 7.8 CVSS integer overflow (CVE-2026-3308) allowing RCE via "crafted" PDFs. With no official patch, sandboxing is vital. Update now. #MuPDF #CyberSecurity #InfoSec #RCE #Vulnerability #PDFSecurity #TechNews #CVE https://securityonline.info/mupdf-integer-overflow-vulnerability-cve-2026-3308-rce/ https://t.co/bbCbTp7nu3

    Post summary

    A new CVE (CVE‑2026‑3308) in Artifex MuPDF is announced with an integer overflow leading to RCE, stating no patch yet and recommending sandboxing as a workaround.

    00010351
    11.0K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🔴 CVE-2026-3308 is old news – but heap overflows in PDF parsers never die. Here’s your evergreen fix for MuPDF on #Debian / #Ubuntu. Read more-> https://tinyurl.com/yc6rcywr https://t.co/8CBlyzFwfd

    Post summary

    The tweet advertises an available fix for CVE‑2026‑3308 in MuPDF on Debian/Ubuntu, providing a link and noting it addresses a heap overflow vulnerability.

    0000074
    1.5K followersView on X
  • Syed Aquib@syedaquib77
    Disclosure

    ⚠️ **Vulnerability Alert:** MuPDF Integer Overflow leading to Heap Out-of-Bounds Write 📅 **Timeline:** Disclosure: 2026-03-31; Patch: MuPDF 1.27.1+ 🆔 **CVE-2026-3308** | 📊 CVSS: 7.8 (HIGH 🟠) | 📈 EPSS: 4.661% 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** MuPDF <= 1.27.0 🔧 **Fixed Versions:** MuPDF 1.27.1+ 🫨 **Attack Vectors:** - Local file processing (opening/parsing crafted PDFs) - Requires user interaction (opening file) - No privileges required 📝 **Summary:** An integer overflow in image decoding (pdf_load_image_imp -> fz_unpack_stream) can produce heap out-of-bounds writes when processing specially crafted PDFs, leading to crashes and potentially arbitrary code execution. Exploitation requires a user to open a malicious PDF and effectiveness depends on local mitigations. 📈 **Impact Scope:** Processing crafted PDFs can trigger an integer overflow during image decoding leading to heap OOB writes; results include crashes (DoS) and potential arbitrary code execution on affected MuPDF versions when a user opens a crafted PDF. 🛡️ **Recommended Actions:** - Update MuPDF to 1.27.1 or later immediately - Block or sandbox untrusted PDFs and avoid opening attachments from untrusted sources - Apply runtime mitigations (ASLR, DEP) and run PDF rendering in least-privileged/sandboxed contexts - Monitor for exploit attempts and update IDS/AV signatures 🪢 **Related Resources:** - https://kb.cert.org/vuls/id/951662 - https://github.com/ArtifexSoftware/mupdf/commit/a26f0142e7d390d4a82c6e5ae0e312e07cc4ec85 🏷 **Tags:** #Cybersecurity #MuPDF #CVE2026_3308

    Post summary

    The advisory announces CVE‑2026‑3308, an integer overflow in MuPDF’s image decoding that can cause heap out‑of‑bounds writes and potential code execution via malicious PDFs, and recommends updating to version 1.27.1+ and applying mitigations.

    0000035
    276 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    MuPDFの整数オーバーフロー脆弱性(CVE-2026-3308) https://rocket-boys.co.jp/security-measures-lab/mupdf-integer-overflow-vulnerability-cve-2026-3308/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    The post announces a new integer overflow flaw in MuPDF (CVE‑2026‑3308) and links to a blog post for further details.

    0000084
    373 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3308 An integer overflow vulnerability in 'pdf-image.c' in Artifex's MuPDF version 1.27.0 allows an attacker to maliciously craft a PDF that can trigger an integer overflow … https://www.cve.org/CVERecord?id=CVE-2026-3308

    Post summary

    The post announces an integer overflow vulnerability in Artifex MuPDF 1.27.0’s pdf-image.c, without providing any PoC, exploit, or mitigation details.

    0000097
    56.9K followersView on X

Explore more