๐Ÿ” CVE Alert

CVE-2026-55586

MEDIUM 6.6

SumatraPDF: Heap out-of-bounds write in vendored CHMLib LZX Huffman table construction reachable from crafted CHM files

CVSS Score
6.6
EPSS Score
0.0%
EPSS Percentile
0th

SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, a crafted CHM file can supply malformed LZX Huffman code lengths to make_decode_table in ext/CHMLib/lzx.c. In the long-code branch, the function writes new internal nodes through next_symbol before validating that the canonical Huffman table has overflowed. The PRETREE case can write beyond the 104-entry PRETREE_table into adjacent heap state in struct LZXstate when reached through chm_open, chm_retrieve_object, LZXdecompress, and BUILD_TABLE. This produces heap memory corruption in the parser process, while arbitrary code execution has not been demonstrated. No fixed version is available as of this review.

CWE CWE-119 CWE-787
Vendor sumatrapdfreader
Product sumatrapdf
Published Aug 20, 2026
Stay Ahead of the Next One

Get instant alerts for sumatrapdfreader sumatrapdf

Be the first to know when new medium vulnerabilities affecting sumatrapdfreader sumatrapdf are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
Low

Affected Versions

sumatrapdfreader / sumatrapdf
<= 3.6.1rel

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/sumatrapdfreader/sumatrapdf/security/advisories/GHSA-m423-rp8p-whj8 github.com: https://github.com/sumatrapdfreader/sumatrapdf/commit/13b3d4204dd12d93d426f2157b157b149edc29bf