CVE-2026-107737

Source
https://cve.org/CVERecord?id=CVE-2026-107737
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107737.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-107737
Aliases
  • GHSA-8p34-f32f-7rmq
Published
2026-10-08T22:34:16Z
Modified
2026-10-10T07:06:08Z
Severity
  • 5.7 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
SumatraPDF CHM `its://` signed index causes an out-of-bounds object lookup
Details

SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, and in pre-release 3.7.0.20369 when WebView2 is absent or cannot initialize, ParseProtoUrl() accepts the signed host component of an its:// URL and FindHtmlWindowById() uses it directly as an index into gHtmlWindows. Opening a crafted CHM through the IE fallback backend with a negative or otherwise out-of-range window identifier can cause an out-of-bounds pointer read followed by an invalid object callback dereference and process termination. No fixed version is available as of this review.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-129"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107737.json"
}
References

Affected packages

Git / github.com/sumatrapdfreader/sumatrapdf

Affected ranges

Type
GIT
Repo
https://github.com/sumatrapdfreader/sumatrapdf
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.6.1"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

1.*
1.4split
1.5split
1.6split
1.7split
1.8split
1.9split
2.*
2.0split
2.1split
2.2split
2.3split
2.4split
2.5split
3.*
3.0split
3.1.2rel
3.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107737.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "313923021044167969583392724138431684161",
                "142563719783934443657751127588730127084",
                "269928050847192063991418633618554423284",
                "163127409971232477253274924047211537254"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107737-6e1b4fde",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/sumatrapdfreader/sumatrapdf/commit/596c7e26e983549a77a3a38cae1147ab73792929",
        "target": {
            "file": "src/wingui/HtmlWindow.cpp"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "28124119988523577615371240111662391885",
            "length": 68
        },
        "id": "CVE-2026-107737-793a4205",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/sumatrapdfreader/sumatrapdf/commit/596c7e26e983549a77a3a38cae1147ab73792929",
        "target": {
            "file": "src/wingui/HtmlWindow.cpp",
            "function": "FindHtmlWindowById"
        }
    }
]
vanir_signatures_modified
"2026-10-10T07:06:08Z"