{"id":"CVE-2026-107737","summary":"SumatraPDF CHM `its://` signed index causes an out-of-bounds object lookup","details":"SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, and in pre-release 3.7.0.20369 when WebView2 is absent or cannot initialize, ParseProtoUrl() accepts the signed host component of an its:// URL and FindHtmlWindowById() uses it directly as an index into gHtmlWindows. Opening a crafted CHM through the IE fallback backend with a negative or otherwise out-of-range window identifier can cause an out-of-bounds pointer read followed by an invalid object callback dereference and process termination. No fixed version is available as of this review.","aliases":["GHSA-8p34-f32f-7rmq"],"modified":"2026-10-10T07:06:08.565722326Z","published":"2026-10-08T22:34:16.436Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-129"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107737.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107737.json"},{"type":"ADVISORY","url":"https://github.com/sumatrapdfreader/sumatrapdf/security/advisories/GHSA-8p34-f32f-7rmq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107737"},{"type":"FIX","url":"https://github.com/sumatrapdfreader/sumatrapdf/commit/596c7e26e983549a77a3a38cae1147ab73792929"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/sumatrapdfreader/sumatrapdf","events":[{"introduced":"0"},{"fixed":"596c7e26e983549a77a3a38cae1147ab73792929"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"0"},{"last_affected":"3.6.1"}]}}],"versions":["3.2","3.1.2rel","3.0split","2.5split","2.4split","2.3split","2.2split","2.1split","2.0split","1.9split","1.8split","1.7split","1.6split","1.5split","1.4split"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107737.json","vanir_signatures":[{"target":{"file":"src/wingui/HtmlWindow.cpp"},"deprecated":false,"digest":{"line_hashes":["313923021044167969583392724138431684161","142563719783934443657751127588730127084","269928050847192063991418633618554423284","163127409971232477253274924047211537254"],"threshold":0.9},"id":"CVE-2026-107737-6e1b4fde","signature_type":"Line","signature_version":"v1","source":"https://github.com/sumatrapdfreader/sumatrapdf/commit/596c7e26e983549a77a3a38cae1147ab73792929"},{"target":{"function":"FindHtmlWindowById","file":"src/wingui/HtmlWindow.cpp"},"deprecated":false,"digest":{"function_hash":"28124119988523577615371240111662391885","length":68},"id":"CVE-2026-107737-793a4205","signature_type":"Function","signature_version":"v1","source":"https://github.com/sumatrapdfreader/sumatrapdf/commit/596c7e26e983549a77a3a38cae1147ab73792929"}],"vanir_signatures_modified":"2026-10-10T07:06:08Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}