CVE-2026-38076

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

An integer overflow in the jbig2_arith_iaid_ctx_new() function of Artifex commit cc37d0 allows attackers to cause a Denial of Service (DoS) via a crafted input.

Published 2026-07-09. Last modified 2026-09-14.