{"id":"GHSA-fhp4-pr5j-46m5","summary":"Muhammara has a NULL pointer dereference in LZWDecode filter when DecodeParms omits EarlyChange key","details":"## Summary\n\nA NULL pointer dereference vulnerability exists in `PDFParser::CreateFilterForStream()` when processing a PDF stream with `/Filter /LZWDecode` and a `/DecodeParms` dictionary that does not contain the `EarlyChange` key. This causes an access violation (0xC0000005) and crashes the process.\n\n## Affected Version\n\nmuhammara \u003c= 6.0.4 (latest)\n\n## Vulnerability Details\n\n**File:** `src/deps/PDFWriter/PDFParser.cpp` line 2107\n\n```cpp\nif (inDecodeParams)\n{\n    PDFObjectCastPtr\u003cPDFInteger\u003e earlyObj(\n        QueryDictionaryObject(inDecodeParams, \"EarlyChange\")\n    );\n    early = earlyObj-\u003eGetValue();  // NULL dereference when EarlyChange key is absent\n}\n```\n\nWhen `inDecodeParams` is non-NULL but lacks the `EarlyChange` key:\n1. `QueryDictionaryObject()` returns NULL\n2. `PDFObjectCastPtr\u003cPDFInteger\u003e(NULL)` wraps NULL\n3. `earlyObj-\u003eGetValue()` dereferences NULL → crash\n\n## PoC\n\n460-byte malicious PDF triggers crash via `startReadingFromStream()`:\n\n- PDF contains `/Filter /LZWDecode` with `/DecodeParms \u003c\u003c \u003e\u003e` (empty, no EarlyChange)\n- Exit code: `0xC0000005` (Access Violation)\n\n## Fix\n\n```cpp\nif (earlyObj)\n    early = earlyObj-\u003eGetValue();\n```\n\n## Impact\n\nAny application accepting untrusted PDFs and using muhammara to read stream contents is vulnerable to DoS.\n\nSimilar to: CVE-2022-41957, CVE-2022-39381\n\n## PoC File\n[poc_muhammara_lzw_null.js](https://github.com/user-attachments/files/27186113/poc_muhammara_lzw_null.js)","modified":"2026-06-26T21:00:09.759527650Z","published":"2026-06-26T20:55:18Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-476"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-06-26T20:55:18Z"},"references":[{"type":"WEB","url":"https://github.com/julianhille/MuhammaraJS/security/advisories/GHSA-fhp4-pr5j-46m5"},{"type":"WEB","url":"https://github.com/julianhille/MuhammaraJS/commit/a98c07780241353334eb65bfca1df025f14be70b"},{"type":"PACKAGE","url":"https://github.com/julianhille/MuhammaraJS"}],"affected":[{"package":{"name":"muhammara","ecosystem":"npm","purl":"pkg:npm/muhammara"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"6.0.5"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 6.0.4","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-fhp4-pr5j-46m5/GHSA-fhp4-pr5j-46m5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}