-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from missing NULL checks on critical function return values, as evidenced by the patches in PR #235 and #238. These patches explicitly added NULL checks to functions like GetGlyphCharString(), GetTableEntry(), and PDF object query methods. The unpatched versions dereferenced these potentially NULL returns when processing malicious PDFs, causing crashes. The affected functions are clearly identified in the commit diffs that fixed these issues by introducing guard clauses.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| hummus | npm | < 2.6.2 | |
| muhammara | npm | >= 3.0.0, < 3.4.0 | 3.4.0 |
| muhammara | npm | < 2.6.2 | 2.6.2 |
Ongoing coverage of React2Shell