Description

An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service via an infinite recursion in the `mutool clean` utility. When processing a crafted PDF file containing cyclic /Next references in the outline structure, the `strip_outline()` function enters infinite recursion

INFO

Published Date :

2025-08-04T00:00:00.000Z

Last Modified :

2025-08-05T16:46:11.289Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-46206 vulnerability.

Vendors Products
Artifex
  • Mupdf

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact