CVE-2026-107731
Deferred Deferred - Pending Action

Heap Overflow in SumatraPDF LIT File Parsing

Vulnerability report for CVE-2026-107731, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

SumatraPDF is a multi-format reader for Windows. In 3.7.0.22298, four independently reachable range-validation variants in src/LitDoc.cpp allow file-controlled offsets and sizes to overflow, narrow to negative values, or wrap before incomplete bounds checks. The affected calculations include contentOffset, the directory expression dirOff64 + dirLen64, and the decoded-section offset + size, along with secondary-header range handling. Opening a crafted LIT file that reaches one of these variants can cause invalid pointer reads and deterministic application termination. No broader impact is claimed beyond the advisory-supported conditions. No fixed version is available as of this review.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sumatrapdfreader sumatrapdf <= 3.7.0.22298

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

SumatraPDF 3.7.0.22298 has four range-validation flaws in LitDoc.cpp that allow file-controlled offsets and sizes to overflow, become negative, or wrap. These issues affect calculations like contentOffset, directory expressions, and decoded-section offsets. Crafted LIT files can trigger invalid pointer reads and force the app to crash deterministically.

Detection Guidance

This vulnerability involves crafted LIT files triggering range-validation issues in SumatraPDF 3.7.0.22298. Detection requires monitoring for application crashes when opening such files or analyzing file parsing behavior. No direct commands are provided, but inspecting SumatraPDF logs or using process monitors during file opening may help identify crashes or invalid memory accesses.

Impact Analysis

Opening a malicious LIT file could crash SumatraPDF, causing loss of unsaved work. No data theft or remote code execution is claimed, but repeated crashes may disrupt workflows. The impact is limited to the application itself.

Compliance Impact

The vulnerability in SumatraPDF 3.7.0.22298 involves file-controlled offsets and sizes leading to invalid pointer reads and application crashes. This does not directly impact compliance with GDPR, HIPAA, or similar standards as it is limited to local application crashes without evidence of data exposure or unauthorized access.

Mitigation Strategies

Avoid opening LIT files from untrusted sources. Disable SumatraPDF's handling of LIT files if possible. Monitor for application crashes when processing such files.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107731. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart