CVE-2025-57248: Sumatrapdfreader Sumatrapdf
High severity, CVSS 7.3. EPSS: 0.2% chance of exploitation in the next 30 days.
A null pointer dereference vulnerability was discovered in SumatraPDF 3.5.2 during the processing of a crafted .djvu file. When the file is opened, the application crashes inside libmupdf.dll, specifically in the DataPool::has_data() function.
Affected products
- Sumatrapdfreader Sumatrapdf: version 3.5.2 only
Published 2025-09-15. Last modified 2026-06-17.