CVE-2026-26054
— UNSCOREDpublic exploit availablePublished 2026-09-24 · Updated 2026-09-28
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
SumatraPDF is a multi-format reader for Windows. Prior to 3.6, the MobiDoc::ParseHeader function in src/MobiDoc.cpp validates a record using kMobiHeaderMinLen but DecodeMobiDocHeader constructs a decoder sized for kMobiHeaderLen without receiving the actual remaining buffer length. A malformed MOBI file can use an attacker-controlled header length to bypass optional-field early returns and cause the decoder to read beyond a short heap buffer. Opening the crafted document can crash SumatraPDF. This issue is fixed in version 3.6.
Weaknesses
CWE-125
Public exploit & PoC references
- https://github.com/sumatrapdfreader/sumatrapdf/commit/24b9ce83383bbaa48b3efe00e4d30cccea126198
- https://github.com/sumatrapdfreader/sumatrapdf/issues/5318
- https://github.com/sumatrapdfreader/sumatrapdf/releases/tag/3.6rel
- https://github.com/sumatrapdfreader/sumatrapdf/security/advisories/GHSA-27p6-wrfp-pgm8
- https://github.com/sumatrapdfreader/sumatrapdf/security/advisories/GHSA-27p6-wrfp-pgm8
All references
- https://github.com/sumatrapdfreader/sumatrapdf/commit/24b9ce83383bbaa48b3efe00e4d30cccea126198
- https://github.com/sumatrapdfreader/sumatrapdf/issues/5318
- https://github.com/sumatrapdfreader/sumatrapdf/releases/tag/3.6rel
- https://github.com/sumatrapdfreader/sumatrapdf/security/advisories/GHSA-27p6-wrfp-pgm8
- https://github.com/sumatrapdfreader/sumatrapdf/security/advisories/GHSA-27p6-wrfp-pgm8
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-100387PoC
- MEDIUMCVE-2026-100505PoC
- MEDIUMCVE-2026-101204
- MEDIUMCVE-2026-101205
- MEDIUMCVE-2026-102318
- HIGHCVE-2026-102360PoC
- MEDIUMCVE-2026-102507PoC
- HIGHCVE-2026-102521PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.