VU#951662: MuPDF by Artifex contains integer overflow vulnerability.
2026-04-07T20:52:09Z•696a383a1eeff6c77378c0b1638d9ab46b845563c681f51716ff9b092503f249
CrewAIHarborIDriveKyvernoLibreChatMuPDFSSRFdefault credentialsgraphql-upload-minimalheap out-of-boundsinteger overflowlocal privilege escalationlog injectionprototype pollutionremote code executionunsafe deserialization
What happened
Collection of multiple CERT/CC vulnerability notes covering several products. Notable issues include: MuPDF integer overflow in pdf_load_image_imp leading to heap out-of-bounds writes (CVE-2026-3308); CrewAI multi-issue chain including Code Interpreter RCE (CVE-2026-2275) and an SSRF (CVE-2026-2286); IDrive Windows client local privilege escalation allowing arbitrary execution as NT AUTHORITY\SYSTEM (CVE-2026-1995); Kyverno CEL-based HTTP functions SSRF allowing namespaced policies to make arbitrary internal requests; Harbor default admin password risk (default Harbor12345) enabling full admin
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- 696a383a1eeff6c77378c0b1638d9ab46b845563c681f51716ff9b092503f249
- Enrichment time
- 2026-04-07T20:52:09Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.