Heap Buffer Over-read in Affinity by Canva Affects Document Files
CVE-2026-101130

3.6LOW

Key Information:

Vendor

Canva

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-101130?

The Affinity by Canva application versions prior to 3.3.1 lack proper bounds checking when processing arrays of strings in Affinity document files. This oversight allows a malicious actor to create a specially crafted Affinity document. Upon opening, this can lead to the exposure of sensitive information from adjacent heap memory or potentially cause the application to crash, posing significant security risks for users.

Affected Version(s)

affinity 0 < 3.3.1

References

CVSS V3.1

Score:
3.6
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Xusheng Li
.