CVE-2026-107737
Deferred Deferred - Pending Action

Out-of-Bounds Read in SumatraPDF via Malicious CHM File

Vulnerability report for CVE-2026-107737, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, and in pre-release 3.7.0.20369 when WebView2 is absent or cannot initialize, ParseProtoUrl() accepts the signed host component of an its:// URL and FindHtmlWindowById() uses it directly as an index into gHtmlWindows. Opening a crafted CHM through the IE fallback backend with a negative or otherwise out-of-range window identifier can cause an out-of-bounds pointer read followed by an invalid object callback dereference and process termination. No fixed version is available as of this review.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sumatrapdfreader sumatrapdf <= 3.6.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-129 The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

SumatraPDF versions 3.6.1 and earlier, and pre-release 3.7.0.20369 when WebView2 is missing or fails to initialize, contain a flaw in ParseProtoUrl() where it accepts a signed host component of an its:// URL. FindHtmlWindowById() then uses this host directly as an index into gHtmlWindows. Crafted CHM files opened via the IE fallback backend with a negative or out-of-range window ID can trigger an out-of-bounds pointer read, leading to an invalid object callback dereference and process termination.

Detection Guidance

This vulnerability involves SumatraPDF improperly handling crafted CHM files via the IE fallback backend, leading to memory corruption. Detection requires checking for SumatraPDF versions 3.6.1 or earlier and pre-release 3.7.0.20369 without WebView2 initialization. Inspect installed SumatraPDF versions and examine CHM file handling logs for crashes or errors.

Impact Analysis

This vulnerability could allow an attacker to crash the SumatraPDF application by exploiting a maliciously crafted CHM file. The crash may result in denial of service or potentially enable further exploitation if combined with other vulnerabilities.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it involves a local out-of-bounds read and process termination in SumatraPDF, not data exposure or privacy violations. However, if exploited to crash the application during document processing, it could indirectly impact operational compliance by disrupting access to required documents.

Mitigation Strategies

Since no fixed version is available, avoid using SumatraPDF for CHM files. Disable the IE fallback backend if possible. Monitor for crashes when opening CHM files and restrict access to untrusted CHM content. Consider alternative document viewers until a patch is released.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107737. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart