CVE-2018-1000051: Artifex Mupdf

High severity, CVSS 7.8. EPSS: 1.7% chance of exploitation in the next 30 days.

Artifex Mupdf version 1.12.0 contains a Use After Free vulnerability in fz_keep_key_storable that can result in DOS / Possible code execution. This attack appear to be exploitable via Victim opens a specially crafted PDF.

Affected products

  • Artifex Mupdf: version 1.12.0 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only

Published 2018-02-09. Last modified 2026-06-17.