Hi, The following vulnerability was published for mupdf. CVE-2026-7233[0]: | A vulnerability was determined in Artifex MuPDF up to 1.28.0. The | impacted element is the function fz_subset_cff_for_gids of the file | subset-cff.c of the component CFF Index Handler. This manipulation | causes out-of-bounds read. The attack can only be executed locally. | The exploit has been publicly disclosed and may be utilized. The | project was informed of the problem early through a bug report but | has not responded yet. https://bugs.ghostscript.com/show_bug.cgi?id=709328 If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-7233 https://www.cve.org/CVERecord?id=CVE-2026-7233 Please adjust the affected versions in the BTS as needed.