CVE-2026-101130: CWE-126 Buffer Over-read in canva affinity
Description
The Affinity by Canva application before 3.3.1 (October 2026 release) did not perform adequate bounds checking when parsing arrays of strings in Affinity document files, leading to a heap buffer over-read. A threat actor could craft an Affinity document that, when opened by a user in Affinity, could disclose the contents of adjacent heap memory in the document's text or result in an application crash.
CVSS v3.1
Score 3.6low
Affected software
canva
affinity
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-101130 is a heap buffer over-read vulnerability in Affinity by Canva prior to version 3.3.1. The issue arises from insufficient bounds checking when parsing arrays of strings in Affinity document files. An attacker can craft a malicious document that, when opened, may disclose adjacent heap memory contents in the document's text or cause an application crash. The CVSS 3.1 base score is 3.6, reflecting low severity with local attack vector, high attack complexity, no privileges required, and user interaction needed.
Potential Impact
Successful exploitation can lead to disclosure of adjacent heap memory contents, potentially exposing sensitive information within the application memory. Additionally, the vulnerability can cause the application to crash, resulting in denial of service. There is no indication of integrity or broader availability impact beyond the application crash. No known exploits are reported in the wild.
Mitigation Recommendations
A fix is available in Affinity by Canva version 3.3.1 and later. Users should upgrade to version 3.3.1 or newer to remediate this vulnerability. No additional mitigation steps are indicated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Canva
- Date Reserved
- 2026-09-28T07:12:04.980Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ac8e6472cdf04f65657df2e
Added to database: 10/09/2026, 13:04:07 UTC
Last enriched: 10/09/2026, 13:18:46 UTC
Last updated: 10/09/2026, 18:57:31 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.