Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-26054— SumatraPDF: Heap out-of-bounds read in MOBI header parser.

Quick assessment

Affected
sumatrapdfreader sumatrapdf
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

SumatraPDF 是一款面向 Windows 的多格式文档阅读器。在 3.6 版本之前,位于 src/MobiDoc.cpp 中的 MobiDoc::ParseHeader 函数使用 kMobiHeaderMinLen 对记录进行验证,但 DecodeMobiDocHeader 在构造解码器时,其大小设定为 kMobiHeaderLen,且未获取实际的剩余缓冲区长度。恶意构造的 MOBI 文件可利用攻击者控制的头长度字段,绕过可选字段的早期返回逻辑,从而导致解码器读取超出短堆缓冲区的边界。打开精心构造的文档可能

CVSS 6.8 · Medium EPSS 0.14% · P3

Possible ATT&CK Techniques 1 AI

T1203 · Exploitation for Client Execution

Affected Version Matrix 1

VendorProduct Version RangeStatus
sumatrapdfreader sumatrapdf < 3.6 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-26054

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
SumatraPDF: Heap out-of-bounds read in MOBI header parser.
Source: CVE Program / CVE List V5
Vulnerability Description
SumatraPDF is a multi-format reader for Windows. Prior to 3.6, the MobiDoc::ParseHeader function in src/MobiDoc.cpp validates a record using kMobiHeaderMinLen but DecodeMobiDocHeader constructs a decoder sized for kMobiHeaderLen without receiving the actual remaining buffer length. A malformed MOBI file can use an attacker-controlled header length to bypass optional-field early returns and cause the decoder to read beyond a short heap buffer. Opening the crafted document can crash SumatraPDF. This issue is fixed in version 3.6.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存读
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
sumatrapdfreader sumatrapdf < 3.6 -

II. Public POCs for CVE-2026-26054

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-26054

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-26054 (2)

Vendor Advisories for CVE-2026-26054 (1)

Vendor Pages for CVE-2026-26054 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-26054

No comments yet


Leave a comment