{"id":"CVE-2025-71382","summary":"MuPDF \u003c 1.27.0-rc1 Stack Exhaustion DoS via EPUB CSS Rendering","details":"MuPDF before 1.27.0-rc1 contains an uncontrolled recursion vulnerability in the EPUB CSS rendering engine that allows remote attackers to cause a denial of service by supplying a maliciously crafted EPUB file with deeply nested HTML elements and inline CSS styles. The function value_from_inheritable_property() in css-apply.c recurses through the CSS property inheritance chain without a depth limit, exhausting the process stack and causing a crash in any application using MuPDF for EPUB rendering.","modified":"2026-08-12T15:15:01.263833Z","published":"2026-06-23T17:21:48.562Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-674"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/71xxx/CVE-2025-71382.json"},"references":[{"type":"ADVISORY","url":"https://github.com/ArtifexSoftware/mupdf/releases/tag/1.27.0-rc1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/71xxx/CVE-2025-71382.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-71382"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/mupdf-rc1-stack-exhaustion-dos-via-epub-css-rendering"},{"type":"FIX","url":"https://github.com/ArtifexSoftware/mupdf/commit/70b71ab22e6de4d4c44cd301c88231f623a4e94e"},{"type":"PACKAGE","url":"https://github.com/ArtifexSoftware/mupdf"},{"type":"EVIDENCE","url":"https://bugs.ghostscript.com/show_bug.cgi?id=708840"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/artifexsoftware/mupdf","events":[{"introduced":"0"},{"fixed":"d3b7556577b790e9761868c314ad6fd9b6dd86a9"},{"fixed":"70b71ab22e6de4d4c44cd301c88231f623a4e94e"},{"fixed":"9d419fc6d9e4caa46e15d8e5d313b2d57c61bfa7"}],"database_specific":{"cpe":"cpe:2.3:a:artifex:mupdf:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.27.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["1.27.0-rc1","1.26.0-rc2","1.26.0-rc1","1.25.0-rc1","1.24.0","1.24.0-rc1","1.23.0","1.23.0-rc1","1.22.0-rc1","1.21.0-rc1","1.20.0-rc1","1.19.0-rc1-so-3.12.7","1.19.0-rc1","1.18.1-so-3.12.6","1.18.1-so-3.12.4","1.18.1-so-3.12.2b1-android","1.18.1-so-3.12.2b1-ios","1.18.1-so-3.12.1-android","1.18.1-so-3.12.1-ios","1.18.0","1.18.0-rc1","1.17.0-rc1","1.16.1","1.16.1-epub-prerelease","1.16.0-rc2","1.16.0","1.16.0-rc1","1.15.0-rc1","1.15.0","1.14.0","1.14.0-rc1","1.13.0-rc1","1.13.0","1.12.0","1.11.1","1.11","1.11-rc1","1.10","1.10-rc2","1.10-rc1","1.9a","1.9","1.9-rc2","1.9-rc1","1.8","1.7a","1.7","1.7-rc1","1.6-appstore","1.6-ios-rc2","1.6-ios-rc1","android-release-60","1.6","1.5-ios-rc8","1.5-ios-appstore","1.5-ios-rc7","1.5-ios-rc6","1.5-ios","1.5","1.4-ios","1.4","1.3rc1","1.2","1.1-forms-tech-preview","1.0","1.0rc1","0.9","0.8","0.7","0.6","0.5","0.4","0.3","0.2","0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-71382.json","vanir_signatures_modified":"2026-08-12T15:15:01Z","vanir_signatures":[{"digest":{"line_hashes":["249366329110280250880974292642454899873","298452772998204583741315718998804186654","246665099913006885487427977143869501424","226495033384969031390017779327972361606","338425939486695600720550229561831337622","101994744914548263347964358038402681842","194120624966045279999943932332826407259","64840780113404501749665532905197575667","311802052120347122654801284142787809768","160447079547790859635261672673514929672","66500399548634781989633676588608957720","127697111726199351237263438510803827579"],"threshold":0.9},"id":"CVE-2025-71382-2aec4753","signature_type":"Line","signature_version":"v1","source":"https://github.com/artifexsoftware/mupdf/commit/70b71ab22e6de4d4c44cd301c88231f623a4e94e","target":{"file":"source/html/css-apply.c"},"deprecated":false},{"signature_version":"v1","source":"https://github.com/artifexsoftware/mupdf/commit/70b71ab22e6de4d4c44cd301c88231f623a4e94e","target":{"file":"source/html/css-apply.c","function":"value_from_inheritable_property"},"deprecated":false,"digest":{"length":284,"function_hash":"211028717704414794691558675982010287858"},"id":"CVE-2025-71382-5d7eb8fc","signature_type":"Function"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}