Buffer Overflow Vulnerability in SumatraPDF Before Version 3.6
CVE-2026-26054

6.8MEDIUM

Key Information:

Vendor
CVE Published:
24 September 2026

What is CVE-2026-26054?

SumatraPDF, a versatile document reader for Windows, contains a buffer overflow vulnerability in its MobiDoc::ParseHeader function. The issue arises when the decoder's size is not correctly aligned with the actual length of the incoming data from a malformed MOBI file. An attacker can exploit this by crafting a malicious document that manipulates the header length, endangering the application's stability and resulting in crashes upon opening such documents. This vulnerability has been addressed in version 3.6.

Affected Version(s)

sumatrapdf < 3.6

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.