CVE-2026-22882: Canva Affinity

High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.

An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

Affected products

  • Canva Affinity: before 3.1.0 (fixed in 3.1.0)

Published 2026-03-17. Last modified 2026-06-17.