Input Validation Issues in SumatraPDF Multi-Format Reader by SumatraPDF
CVE-2026-107731

5.5MEDIUM

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107731?

The SumatraPDF multi-format reader for Windows has introduced input validation vulnerabilities in version 3.7.0.22298. These vulnerabilities involve four independently reachable range-validation variants in the source code file src/LitDoc.cpp. They permit file-controlled offsets and sizes to overflow, potentially becoming negative values or wrapping incorrectly due to insufficient bounds checks. A crafted LIT file can exploit these vulnerabilities, leading to invalid pointer reads and deterministic application crashes. Currently, no patched version is available, and users are encouraged to remain vigilant while handling LIT files.

Affected Version(s)

sumatrapdf <= 3.7.0.22298

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.