Heap Buffer Over-read in Affinity by Canva Document Files
CVE-2026-101094

3.6LOW

Key Information:

Vendor

Canva

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-101094?

A vulnerability exists in Affinity by Canva prior to version 3.3.1 that improperly processes incomplete UTF-8 character sequences when handling Affinity document files. This flaw permits a threat actor to craft a malicious Affinity document that, upon being accessed by a user, can reveal adjacent memory contents or cause the application to crash. Users are urged to update to the latest version to mitigate potential risks.

Affected Version(s)

affinity 0 < 3.3.1

References

CVSS V3.1

Score:
3.6
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Xusheng Li
.