Denial of Service Vulnerability in SumatraPDF Multi-Format Reader from SumatraPDF
CVE-2026-107733
6.8MEDIUM
What is CVE-2026-107733?
The SumatraPDF application, a versatile PDF and multi-format reader for Windows, is susceptible to a Denial of Service vulnerability in versions up to 3.6.1. The issue arises from the FrameOnCommand() function, which passes a null pointer during command execution, leading to abrupt termination of the application when no document tabs are open. A local process within the same interactive Windows session can exploit this flaw, potentially resulting in the loss of unsaved work. As of now, there is no patch available to mitigate this vulnerability.
Affected Version(s)
sumatrapdf <= 3.6.1
