Buffer Overflow Vulnerability in SumatraPDF Before Version 3.6
CVE-2026-26054
6.8MEDIUM
What is CVE-2026-26054?
SumatraPDF, a versatile document reader for Windows, contains a buffer overflow vulnerability in its MobiDoc::ParseHeader function. The issue arises when the decoder's size is not correctly aligned with the actual length of the incoming data from a malformed MOBI file. An attacker can exploit this by crafting a malicious document that manipulates the header length, endangering the application's stability and resulting in crashes upon opening such documents. This vulnerability has been addressed in version 3.6.
Affected Version(s)
sumatrapdf < 3.6
