CVE-2025-66503: High severity Canva Affinity vulnerability
Published Mar 17, 2026
·Updated
An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.
Affected Software
2 affected components
Canva Affinity
Canva Affinity Windows<3.1.0
Event History
Mar 17, 2026
CVE Published
via MITRE·06:52 PM
Data Sourced
via MITRE·06:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-66503?
CVE-2025-66503 is considered a medium severity vulnerability due to the potential for sensitive information disclosure.
2
How do I fix CVE-2025-66503?
To mitigate CVE-2025-66503, users should update Canva Affinity to the latest version beyond 3.1.0.
3
What type of vulnerability is CVE-2025-66503?
CVE-2025-66503 is categorized as an out-of-bounds read vulnerability.
4
What impact does CVE-2025-66503 have if exploited?
Exploitation of CVE-2025-66503 could lead to the disclosure of sensitive information.
5
Which software is affected by CVE-2025-66503?
CVE-2025-66503 affects Canva Affinity, specifically versions prior to 3.1.0 on Windows.