CVE-2026-25920: Sumatrapdfreader Sumatrapdf
Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.
SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, a heap out-of-bounds read vulnerability exists in SumatraPDF's MOBI HuffDic decompressor. The bounds check in AddCdicData() only validates half the range that DecodeOne() actually accesses. Opening a crafted .mobi file can read nearly (1 << codeLength) bytes beyond the CDIC dictionary buffer, leading to a crash.
Affected products
- Sumatrapdfreader Sumatrapdf: up to and including 3.5.2
Published 2026-02-09. Last modified 2026-06-17.