Uncontrolled Recursion Vulnerability in MuPDF EPUB Rendering Engine
CVE-2025-71382
Key Information:
- Vendor
Artifexsoftware
- Status
- Vendor
- CVE Published:
- 23 June 2026
Badges
What is CVE-2025-71382?
MuPDF, a document rendering software, is vulnerable due to an uncontrolled recursion issue in its EPUB CSS rendering engine. This vulnerability allows remote attackers to exploit deeply nested HTML elements and inline CSS styles in specially crafted EPUB files. By triggering this vulnerability, attackers can exhaust the process stack, resulting in a denial of service for any application that utilizes MuPDF for EPUB rendering. This can render applications crash without proper safeguards in place.
Affected Version(s)
mupdf 0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
