CVE-2025-46206 affects Artifex MuPDF versions 1.25.6 and 1.25.5. The issue is an infinite recursion flaw in the mutool clean utility when it processes a crafted PDF file containing cyclic /Next references in the document outline structure. During outline handling, the strip_outline() function recursively traverses outline nodes without safely handling cycles, which can cause unbounded recursion when a malicious PDF introduces a reference loop.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
mutool clean. Processing a malicious PDF can drive the utility into infinite recursion, leading to stack exhaustion, process hang, or crash, preventing successful document cleaning and potentially disrupting any workflow or service that automatically invokes the utility on untrusted PDFs.If you can’t patch tonight, do this now.
mutool clean. Where immediate patching is not possible, isolate PDF processing in a sandboxed environment with strict CPU time, memory, and stack limits, and use process supervision/timeouts to terminate hung conversions. Pre-screen PDFs for malformed or cyclic outline structures where feasible.Patch, then assume compromise.
strip_outline() or equivalent outline traversal code. If no fixed version information is currently available, monitor vendor advisories and apply the first patched release.1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a proof-of-concept (POC) exploit for a denial of service vulnerability in MuPDF version 1.25.6 and earlier. The exploit consists of a single malicious PDF file ('mupdf-clean-poc') and a README.md file describing the vulnerability and how to reproduce it. The exploit works by running the command 'mutool clean mupdf-clean-poc /dev/null', which causes MuPDF to enter infinite recursion in its outline processing code, leading to stack exhaustion and a crash. The vulnerability has been acknowledged and fixed by the vendor. The repository is structured simply, with the POC PDF as the main payload and no additional scripts or code. The attack vector is local, requiring the attacker to execute the command with the malicious file on a vulnerable system.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.