CVE WATCH / VULNERABILITY DETAIL

CVE-2026-103220

MEDIUMCVSS 4.5NVD feed

Published 9 October 2026 · tracked since 10 October 2026

Description

The Affinity by Canva application before 3.3.1 (October 2026 release) did not perform adequate bounds checking when parsing raster image data in Affinity document files, leading to an out-of-bounds read and the dereference of an untrusted pointer. A threat actor could craft an Affinity document that

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-103220 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-103220

MEDIUMCVSS 4.5NVD feed

Published 9 October 2026 · tracked since 10 October 2026

Description

The Affinity by Canva application before 3.3.1 (October 2026 release) did not perform adequate bounds checking when parsing raster image data in Affinity document files, leading to an out-of-bounds read and the dereference of an untrusted pointer. A threat actor could craft an Affinity document that

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]