Junglewise Threat Intelligence

CVE-2025-71382: Artifex MuPDF uncontrolled recursion in EPUB CSS rendering

CVE-2025-71382 · Severity: medium · CVSS 6.5 · Published 2026-06-23

Vendors: Artifex Software.

Executive brief

MuPDF, a widely used library for viewing PDF, XPS, and eBook documents, is vulnerable to a flaw that can cause applications to crash. By tricking a user into opening a specially crafted EPUB eBook file, an attacker can trigger a system crash, leading to a denial of service. This impact affects any software that relies on MuPDF to display eBook content.

Technical details

An uncontrolled recursion vulnerability exists in MuPDF's EPUB rendering component, specifically within the value_from_inheritable_property() function in css-apply.c. The engine fails to impose a depth limit when recursing through the CSS property inheritance chain for deeply nested HTML elements and inline styles. An attacker can exploit this by providing a maliciously crafted EPUB file containing thousands of nested tags, leading to stack exhaustion and a process crash. The issue is resolved in version 1.27.0-rc1 by replacing the recursive logic with an iterative approach.

Affected products

  • Artifex Software MuPDF before 1.27.0-rc1

Timeline

  • 2025-09-13: disclosed: Initial bug report to Ghostscript Bugzilla
  • 2025-10-19: patched: Fix committed to MuPDF repository
  • 2026-06-23: advisory: NVD publication date

References