CVE-2018-19777: Artifex Mupdf

Medium severity, CVSS 5.5. EPSS: 1.1% chance of exploitation in the next 30 days.

In Artifex MuPDF 1.14.0, there is an infinite loop in the function svg_dev_end_tile in fitz/svg-device.c, as demonstrated by mutool.

Affected products

  • Artifex Mupdf: version 1.14.0 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only

Published 2018-11-30. Last modified 2026-06-17.