Out-of-Bounds Read Vulnerability in Affinity by Canva Application
CVE-2026-103220

4.5MEDIUM

Key Information:

Vendor

Canva

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-103220?

The Affinity by Canva application versions prior to 3.3.1 lack proper bounds checking during the parsing of raster image data. This vulnerability allows a malicious actor to create a specially crafted Affinity document that, when opened, may result in memory corruption or even cause the application to crash due to the dereferencing of an untrusted pointer. Users should be wary of opening files from untrusted sources to mitigate potential risks.

Affected Version(s)

affinity 0 < 3.3.1

References

CVSS V3.1

Score:
4.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Xusheng Li
.