Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
EPEL9 has mupdf-1.21 which does not even belong to the range reported in the CVE. Doesn't anyone check these reports?