CVE-2026-107730
Last modified
CVE-2026-107730 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. SumatraPDF is a multi-format reader for Windows. In 3.7.0.22298, LitParseHeader() in src/LitDoc.cpp computes the attacker-controlled hdrLen + nPieces * 16 section offset using signed 32-bit arithmetic without validating the complete result. EPSS estimates a 0.12% chance of exploitation in the next 30 days.
Description
SumatraPDF is a multi-format reader for Windows. In 3.7.0.22298, LitParseHeader() in src/LitDoc.cpp computes the attacker-controlled hdrLen + nPieces * 16 section offset using signed 32-bit arithmetic without validating the complete result. When the component values make that aggregate calculation overflow to a negative value, pointer construction reaches an invalid read in LitU32(), causing deterministic application termination. The supplied evidence does not demonstrate code execution, information disclosure, arbitrary read, or integrity impact. No fixed version is available as of this review.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-107730?
How severe is CVE-2026-107730?
How do I fix CVE-2026-107730?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-107725Hazelcast is a unified real-time data platform combining str…8.7
- CVE-2026-107726Hazelcast is a unified real-time data platform combining str…9.3
- CVE-2026-107727Strawberry GraphQL is a library for creating GraphQL APIs. F…3.7
- CVE-2026-107728Strawberry GraphQL is a library for creating GraphQL APIs. F…7.5
- CVE-2026-107729SumatraPDF is a multi-format reader for Windows. In 3.7.0.22…5.5
- CVE-2026-10773The DHCPv4 client helper net_dhcpv4_msg_type_name() in subsy…5.4
- CVE-2026-107731SumatraPDF is a multi-format reader for Windows. In 3.7.0.22…5.5
- CVE-2026-107732SumatraPDF is a multi-format reader for Windows. In 3.6.1 an…8.4
- CVE-2026-107733SumatraPDF is a multi-format reader for Windows. In 3.6.1 an…6.8
- CVE-2026-107734SumatraPDF is a multi-format reader for Windows. In 3.5.2 an…7.1
- CVE-2026-107735SumatraPDF is a multi-format reader for Windows. In 3.6.1 an…5.4
- CVE-2026-107736SumatraPDF is a multi-format reader for Windows. In 3.6.1 an…6.8
Are you affected by CVE-2026-107730?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
