CVE-2025-57248: Sumatrapdfreader Sumatrapdf

High severity, CVSS 7.3. EPSS: 0.2% chance of exploitation in the next 30 days.

A null pointer dereference vulnerability was discovered in SumatraPDF 3.5.2 during the processing of a crafted .djvu file. When the file is opened, the application crashes inside libmupdf.dll, specifically in the DataPool::has_data() function.

Affected products

Published 2025-09-15. Last modified 2026-06-17.