CVE-2026-101094: Low severity Canva Affinity vulnerability
The Affinity by Canva application before 3.3.1 (October 2026 release) did not correctly handle incomplete UTF-8 character sequences when parsing text in Affinity document files, leading to a heap buffer over-read. A threat actor could craft an Affinity document that, when opened by a user in Affinity, could disclose the contents of adjacent heap memory in the document's text or result in an application crash.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Affinity by Canvato a version that resolves this vulnerability.Fixed in 3.3.1
Event History
Frequently Asked Questions
Who is exposed to exploitation?
Users of Affinity by Canva versions before 3.3.1 are exposed if they open a crafted Affinity document. Exploitation requires user interaction; the attacker must induce a user to open the malicious file.
What can exploitation do?
A crafted document can cause Affinity to disclose adjacent heap-memory contents in the document text or crash the application. The provided severity vector indicates local attack conditions, high attack complexity, no required privileges, and user interaction.
Which version fixes the issue?
Affinity by Canva 3.3.1, identified as the October 2026 release, fixes the incomplete UTF-8 sequence handling issue.