CVE-2026-107729
Deferred Deferred - Pending Action

Integer Overflow in SumatraPDF MOBI File Handling

Vulnerability report for CVE-2026-107729, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

SumatraPDF is a multi-format reader for Windows. In 3.7.0.22298, src/MobiDoc.cpp narrows the untrusted unsigned mobiHdr.hdrLen field to a signed integer for validation; values above INT_MAX become negative and bypass the upper-bound check. When the EXTH flag is set, the original unsigned value is reused as a pointer offset, causing DecodeExthHeader() to read beyond the record buffer. Opening a crafted MOBI file can reliably terminate the application with a native access violation; no code execution, information disclosure, or integrity impact has been demonstrated. No fixed version is available as of this review.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sumatrapdfreader sumatrapdf <= 3.7.0.22298

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

SumatraPDF 3.7.0.22298 has an integer overflow vulnerability in src/MobiDoc.cpp. The mobiHdr.hdrLen field, which is unsigned, is narrowed to a signed integer for validation. If the value exceeds INT_MAX, it becomes negative and bypasses upper-bound checks. When the EXTH flag is set, the original unsigned value is used as a pointer offset, causing DecodeExthHeader() to read beyond the record buffer. This can crash the application with a native access violation.

Detection Guidance

This vulnerability is triggered by opening a crafted MOBI file in SumatraPDF 3.7.0.22298. Detection requires monitoring for crashes when processing such files. Check SumatraPDF logs or Windows Event Viewer for application termination errors after opening MOBI files. No specific commands are provided in the context.

Impact Analysis

Opening a specially crafted MOBI file could cause SumatraPDF to crash. The impact is limited to denial of service (application termination) as no code execution, information disclosure, or integrity impact has been demonstrated.

Compliance Impact

This vulnerability does not directly impact compliance with GDPR, HIPAA, or similar standards as it only causes application crashes without data exposure or integrity loss. However, denial of service could affect availability, which may be relevant for service-level agreements or operational resilience requirements.

Mitigation Strategies

Avoid opening MOBI files from untrusted sources. Disable SumatraPDF or use an alternative PDF reader until a patch is released. Monitor for updates from SumatraPDF developers for a fixed version.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107729. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart