Denial of Service Vulnerability in SumatraPDF Multi-Format Reader from SumatraPDF
CVE-2026-107733

6.8MEDIUM

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107733?

The SumatraPDF application, a versatile PDF and multi-format reader for Windows, is susceptible to a Denial of Service vulnerability in versions up to 3.6.1. The issue arises from the FrameOnCommand() function, which passes a null pointer during command execution, leading to abrupt termination of the application when no document tabs are open. A local process within the same interactive Windows session can exploit this flaw, potentially resulting in the loss of unsaved work. As of now, there is no patch available to mitigate this vulnerability.

Affected Version(s)

sumatrapdf <= 3.6.1

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.