An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 17 Mar 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Canva
Canva affinity |
|
| CPEs | cpe:2.3:a:canva:affinity:-:*:*:*:*:windows:*:* | |
| Vendors & Products |
Canva
Canva affinity |
Tue, 17 Mar 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information. | |
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: talos
Published:
Updated: 2026-03-17T20:11:38.448Z
Reserved: 2026-01-14T15:54:57.953Z
Link: CVE-2026-20726
No data.
Status : Received
Published: 2026-03-17T19:16:00.430
Modified: 2026-03-17T19:16:00.430
Link: CVE-2026-20726
No data.
OpenCVE Enrichment
No data.
Weaknesses