CVE-2026-7233: Artifex MuPDF CFF Index subset-cff.c fz_subset_cff_for_gids out-of-bounds
A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fzsubsetcffforgids of the file subset-cff.c of the component CFF Index Handler. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through a bug report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7233?
CVE-2026-7233 is classified as a medium-severity vulnerability.
How do I fix CVE-2026-7233?
To fix CVE-2026-7233, upgrade Artifex MuPDF to version 1.28.1 or later.
What software is affected by CVE-2026-7233?
CVE-2026-7233 affects Artifex MuPDF versions up to and including 1.28.0.
What type of vulnerability is CVE-2026-7233?
CVE-2026-7233 is an out-of-bounds read vulnerability in the CFF Index Handler.
Where can I find more information about CVE-2026-7233?
Details about CVE-2026-7233 can typically be found in security advisories and vulnerability databases.