VU#951662: MuPDF by Artifex contains integer overflow vulnerability.

2026-04-07T20:52:09Z696a383a1eeff6c77378c0b1638d9ab46b845563c681f51716ff9b092503f249
CrewAIHarborIDriveKyvernoLibreChatMuPDFSSRFdefault credentialsgraphql-upload-minimalheap out-of-boundsinteger overflowlocal privilege escalationlog injectionprototype pollutionremote code executionunsafe deserialization

What happened

Collection of multiple CERT/CC vulnerability notes covering several products. Notable issues include: MuPDF integer overflow in pdf_load_image_imp leading to heap out-of-bounds writes (CVE-2026-3308); CrewAI multi-issue chain including Code Interpreter RCE (CVE-2026-2275) and an SSRF (CVE-2026-2286); IDrive Windows client local privilege escalation allowing arbitrary execution as NT AUTHORITY\SYSTEM (CVE-2026-1995); Kyverno CEL-based HTTP functions SSRF allowing namespaced policies to make arbitrary internal requests; Harbor default admin password risk (default Harbor12345) enabling full admin

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
696a383a1eeff6c77378c0b1638d9ab46b845563c681f51716ff9b092503f249
Enrichment time
2026-04-07T20:52:09Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.