CVE-2026-25920: Sumatrapdfreader Sumatrapdf

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, a heap out-of-bounds read vulnerability exists in SumatraPDF's MOBI HuffDic decompressor. The bounds check in AddCdicData() only validates half the range that DecodeOne() actually accesses. Opening a crafted .mobi file can read nearly (1 << codeLength) bytes beyond the CDIC dictionary buffer, leading to a crash.

Affected products

Published 2026-02-09. Last modified 2026-06-17.