Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT. https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Since the reproducer is private, it is not clear whether EPEL 9 is affected. EPEL 9 carries mupdf 1.21.1. The relevant codepaths (which the fix touches) appear to be introduced by 9cb176d87 ("Simplify overflow-wrap: break-word handling.", 2023-03-24) which is in 1.22.0 and later. I therefore conclude that EPEL 9 ist most probably not affected (NOTABUG), and not fixable anyways (unless by a version jump, CANTFIX).