{"api_version":"1","generated_at":"2026-10-09T11:08:58+00:00","cve":"CVE-2026-107730","urls":{"html":"https://cve.report/CVE-2026-107730","api":"https://cve.report/api/cve/CVE-2026-107730.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-107730","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-107730"},"summary":{"title":"SumatraPDF: Signed integer overflow in the LIT header parsing causes invalid-pointer read","description":"SumatraPDF is a multi-format reader for Windows. In 3.7.0.22298, LitParseHeader() in src/LitDoc.cpp computes the attacker-controlled hdrLen + nPieces * 16 section offset using signed 32-bit arithmetic without validating the complete result. When the component values make that aggregate calculation overflow to a negative value, pointer construction reaches an invalid read in LitU32(), causing deterministic application termination. The supplied evidence does not demonstrate code execution, information disclosure, arbitrary read, or integrity impact. No fixed version is available as of this review.","state":"PUBLISHED","assigner":"GitHub_M","published_at":"2026-10-08 23:16:58","updated_at":"2026-10-08 23:16:58"},"problem_types":["CWE-190","CWE-190 CWE-190: Integer Overflow or Wraparound"],"metrics":[{"version":"3.1","source":"security-advisories@github.com","type":"Secondary","score":"5.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"5.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","data":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","version":"3.1"}}],"references":[{"url":"https://github.com/sumatrapdfreader/sumatrapdf/commit/10a83278a5a6f67194dedfb67c47474d22ecfe4b","name":"https://github.com/sumatrapdfreader/sumatrapdf/commit/10a83278a5a6f67194dedfb67c47474d22ecfe4b","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/sumatrapdfreader/sumatrapdf/security/advisories/GHSA-vfpj-qhvj-92wg","name":"https://github.com/sumatrapdfreader/sumatrapdf/security/advisories/GHSA-vfpj-qhvj-92wg","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-107730","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107730","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"sumatrapdfreader","product":"sumatrapdf","version":"affected <= 3.7.0.22298","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"product":"sumatrapdf","vendor":"sumatrapdfreader","versions":[{"status":"affected","version":"<= 3.7.0.22298"}]}],"descriptions":[{"lang":"en","value":"SumatraPDF is a multi-format reader for Windows. In 3.7.0.22298, LitParseHeader() in src/LitDoc.cpp computes the attacker-controlled hdrLen + nPieces * 16 section offset using signed 32-bit arithmetic without validating the complete result. When the component values make that aggregate calculation overflow to a negative value, pointer construction reaches an invalid read in LitU32(), causing deterministic application termination. The supplied evidence does not demonstrate code execution, information disclosure, arbitrary read, or integrity impact. No fixed version is available as of this review."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-190","description":"CWE-190: Integer Overflow or Wraparound","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-10-08T22:19:46.900Z","orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M"},"references":[{"name":"https://github.com/sumatrapdfreader/sumatrapdf/security/advisories/GHSA-vfpj-qhvj-92wg","tags":["x_refsource_CONFIRM"],"url":"https://github.com/sumatrapdfreader/sumatrapdf/security/advisories/GHSA-vfpj-qhvj-92wg"},{"name":"https://github.com/sumatrapdfreader/sumatrapdf/commit/10a83278a5a6f67194dedfb67c47474d22ecfe4b","tags":["x_refsource_MISC"],"url":"https://github.com/sumatrapdfreader/sumatrapdf/commit/10a83278a5a6f67194dedfb67c47474d22ecfe4b"}],"source":{"advisory":"GHSA-vfpj-qhvj-92wg","discovery":"UNKNOWN"},"title":"SumatraPDF: Signed integer overflow in the LIT header parsing causes invalid-pointer read"}},"cveMetadata":{"assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","assignerShortName":"GitHub_M","cveId":"CVE-2026-107730","datePublished":"2026-10-08T22:19:46.900Z","dateReserved":"2026-10-08T17:21:52.976Z","dateUpdated":"2026-10-08T22:19:46.900Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-08 23:16:58","lastModifiedDate":"2026-10-08 23:16:58","problem_types":["CWE-190","CWE-190 CWE-190: Integer Overflow or Wraparound"],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":3.6}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"107730","Ordinal":"1","Title":"SumatraPDF: Signed integer overflow in the LIT header parsing ca","CVE":"CVE-2026-107730","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"107730","Ordinal":"1","NoteData":"SumatraPDF is a multi-format reader for Windows. In 3.7.0.22298, LitParseHeader() in src/LitDoc.cpp computes the attacker-controlled hdrLen + nPieces * 16 section offset using signed 32-bit arithmetic without validating the complete result. When the component values make that aggregate calculation overflow to a negative value, pointer construction reaches an invalid read in LitU32(), causing deterministic application termination. The supplied evidence does not demonstrate code execution, information disclosure, arbitrary read, or integrity impact. No fixed version is available as of this review.","Type":"Description","Title":"SumatraPDF: Signed integer overflow in the LIT header parsing ca"}]}}}