PatchSiren

Artifex Software CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Artifex Software CVE published 2026-09-15

CVE-2026-39919

A critical vulnerability exists in Ghostscript before version 10.08.0, which could allow attackers to cause memory corruption and potentially execute arbitrary code by supplying a crafted PDF containing a JPEG 2000 image with mismatched component subsampling factors. This vulnerability is particularly concerning as it can be exploited through seemingly innocuous PDF files, which are commonly shared and pr [truncated]

HIGH Artifex Software CVE published 2026-07-09

CVE-2026-38076

CVE-2026-38076 is a high-severity vulnerability in the jbig2dec library, which could allow attackers to cause a Denial of Service (DoS) via a crafted input. The vulnerability has a CVSS score of 7.5 and is classified as HIGH. It was published on 2026-07-09T22:17:03.983Z and last modified on 2026-09-14T14:17:07.643Z. The vulnerability is caused by an integer overflow in the jbig2_arith_iaid_ctx_new() funct [truncated]

MEDIUM Artifex Software CVE published 2026-02-06

CVE-2026-25556

MuPDF versions 1.23.0 through 1.27.0 contain a double-free vulnerability in fz_fill_pixmap_from_display_list() when an exception occurs during display list rendering. This can lead to a double-free error when the caller also drops the same pixmap in cleanup, potentially corrupting the heap and crashing the process. Developers and users of MuPDF library, especially those who enable and use MuPDF barcode de [truncated]