Intel

AIKIDO-2025-10028

PyMuPDF is vulnerable to Denial of Service (DoS)

Denial of Service (DoS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jan 20, 2025

15

Low Risk

This Affects:

pythonPyMuPDF
1.18.17 - 1.25.1
Fixed in 1.25.2
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to a crash when samples_mv is used after the original Pixmap has been deallocated. This flaw can be exploited by malicious actors to trigger a Denial of Service (DoS).

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

PyMuPDF is vulnerable to Denial of Service (DoS) in versions 1.18.17 - 1.25.1.

How to fix this

Upgrade the PyMuPDF library to the patch version.