---
id: CVE-2026-107730
title: SumatraPDF is a multi-format reader for Windows
summary: >-
  SumatraPDF is a multi-format reader for Windows. In 3.7.0.22298,
  LitParseHeader() in src/LitDoc.cpp computes the attacker-controlled hdrLen +
  nPieces * 16 section offset using signed 32-bit arithmetic without validating
  the complete resu…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'
cwe:
  - CWE-190
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T23:16:58.663'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107730'
references:
  - url: >-
      https://github.com/sumatrapdfreader/sumatrapdf/commit/10a83278a5a6f67194dedfb67c47474d22ecfe4b
    label: security-advisories@github.com
  - url: >-
      https://github.com/sumatrapdfreader/sumatrapdf/security/advisories/GHSA-vfpj-qhvj-92wg
    label: security-advisories@github.com
tags:
  - nvd
ingestedAt: '2026-10-09T00:19:50.970Z'
---

## Overview

SumatraPDF is a multi-format reader for Windows. In 3.7.0.22298, LitParseHeader() in src/LitDoc.cpp computes the attacker-controlled hdrLen + nPieces * 16 section offset using signed 32-bit arithmetic without validating the complete result. When the component values make that aggregate calculation overflow to a negative value, pointer construction reaches an invalid read in LitU32(), causing deterministic application termination. The supplied evidence does not demonstrate code execution, information disclosure, arbitrary read, or integrity impact. No fixed version is available as of this review.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
