{"id":"CVE-2026-107731","title":"SumatraPDF is a multi-format reader for Windows","summary":"SumatraPDF is a multi-format reader for Windows. In 3.7.0.22298, four independently reachable range-validation variants in src/LitDoc.cpp allow file-controlled offsets and sizes to overflow, narrow to negative values, or wrap before inco…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":["CWE-125"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T23:16:58.833","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-107731","references":[{"url":"https://github.com/sumatrapdfreader/sumatrapdf/commit/5d43b8cf9c45335ffd47e616bfa27648f17d0b63","label":"security-advisories@github.com"},{"url":"https://github.com/sumatrapdfreader/sumatrapdf/security/advisories/GHSA-753j-hx3p-xm9g","label":"security-advisories@github.com"}],"tags":["nvd"],"ingestedAt":"2026-10-09T00:19:50.970Z","slug":"CVE-2026-107731","body":"## Overview\n\nSumatraPDF is a multi-format reader for Windows. In 3.7.0.22298, four independently reachable range-validation variants in src/LitDoc.cpp allow file-controlled offsets and sizes to overflow, narrow to negative values, or wrap before incomplete bounds checks. The affected calculations include contentOffset, the directory expression dirOff64 + dirLen64, and the decoded-section offset + size, along with secondary-header range handling. Opening a crafted LIT file that reaches one of these variants can cause invalid pointer reads and deterministic application termination. No broader impact is claimed beyond the advisory-supported conditions. No fixed version is available as of this review.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}