-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from a missing NULL check in PDFParser::ParseLastXrefPosition. The patch adds a critical null check after calling mObjectParser.ParseNewObject(), confirming that prior versions would dereference a null pointer when parsing truncated PDF files. The test case added in the commit (BrokenPdfBadHeader.txt) triggers this code path, and the CWE-690 classification directly maps to this unchecked return value scenario.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| muhammara | npm | < 2.6.1 | 2.6.1 |
| muhammara | npm | >= 3.0.0, < 3.1.1 | 3.1.1 |
| hummus | npm |
| < 1.0.111 |
| 1.0.111 |
KEV Misses 88% of Exploited CVEs- Get the report