CVE-2026-55586: CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer in sumatrapdfreader sumatrapdf
Description
SumatraPDF versions 3.6.1 and earlier contain a heap memory corruption vulnerability in the CHM file parser. A crafted CHM file with malformed LZX Huffman code lengths can cause out-of-bounds writes in the decompression code, leading to heap corruption. While arbitrary code execution has not been demonstrated, the flaw poses a risk of memory corruption during parsing. No fixed version is currently available.
CVSS v3.1
Score 6.6medium
Affected software
sumatrapdfreader
sumatrapdf
pkg:github/sumatrapdfreader/sumatrapdfRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-55586 is a heap memory corruption vulnerability in SumatraPDF (<=3.6.1) caused by improper bounds checking in the LZX decompression code for CHM files. Specifically, malformed LZX Huffman code lengths can trigger out-of-bounds writes beyond the 104-entry PRETREE_table into adjacent heap memory within the LZXstate structure. This occurs in the make_decode_table function in ext/CHMLib/lzx.c during the PRETREE case when processing crafted CHM files. The vulnerability can be reached through functions such as chm_open, chm_retrieve_object, LZXdecompress, and BUILD_TABLE. Although heap corruption occurs, no public exploit or arbitrary code execution has been confirmed. No patch or fixed version is available as of the latest review.
Potential Impact
The vulnerability causes heap memory corruption in the SumatraPDF process when parsing specially crafted CHM files. This can lead to application instability or crashes. While the CVSS score indicates low confidentiality impact, high integrity impact, and low availability impact, arbitrary code execution has not been demonstrated or confirmed. There are no known exploits in the wild.
Mitigation Recommendations
No official fix or patch is currently available for this vulnerability. Users should avoid opening untrusted or suspicious CHM files with affected versions of SumatraPDF (3.6.1 and earlier) until a vendor update is released. Monitor the vendor advisory for future remediation guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-16T23:18:03.169Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a8730d9acd9273b49e17189
Added to database: 08/20/2026, 16:52:41 UTC
Last enriched: 09/11/2026, 04:33:05 UTC
Last updated: 10/04/2026, 18:53:17 UTC
Views: 81
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.