CVE-2026-26054

MEDIUM CVSS 4.0: 6.8 EPSS 0.14%
Updated Sep 28, 2026
Sumatrapdf
Parameter Value
CVSS 6.8 (MEDIUM)
Fixed In 3.6
Type CWE-125 (Out-of-bounds Read)
Vendor Sumatrapdf
Public PoC No

SumatraPDF is a multi-format reader for Windows. Prior to 3.6, the MobiDoc::ParseHeader function in src/MobiDoc.cpp validates a record using kMobiHeaderMinLen but DecodeMobiDocHeader constructs a decoder sized for kMobiHeaderLen without receiving the actual remaining buffer length. A malformed MOBI file can use an attacker-controlled header length to bypass optional-field early returns and cause the decoder to read beyond a short heap buffer.

Opening the crafted document can crash SumatraPDF. This issue is fixed in version 3.6.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
None
No privileges needed
User Interaction
Passive
Minimal interaction

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
High
Complete denial of service

CVSS Vector v4.0

Weakness Type (CWE)

Related Vulnerabilities