PatchSiren

sumatrapdfreader CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM sumatrapdfreader CVE published 2026-09-24

CVE-2026-26054

A vulnerability in SumatraPDF, a multi-format reader for Windows, allows for a crash when opening a crafted MOBI document. The issue arises from improper validation of the MOBI file header, leading to a potential read beyond a short heap buffer. This problem is fixed in SumatraPDF version 3.6. Defenders should assess exposure and prioritize updating to version 3.6 or later to prevent potential crashes fro [truncated]

MEDIUM sumatrapdfreader CVE published 2026-08-20

CVE-2026-55586

A crafted CHM file can cause heap memory corruption in SumatraPDF 3.6.1 and earlier due to malformed LZX Huffman code lengths. This vulnerability allows attackers to potentially corrupt heap memory in the parser process. Defenders should assess exposure and prioritize verification and mitigation. The CVE record and NVD entry provide details on the vulnerability, but no fixed version is available. SumatraP [truncated]