CVE-2026-103220: Out-of-bounds Read
The Affinity by Canva application before 3.3.1 (October 2026 release) did not perform adequate bounds checking when parsing raster image data in Affinity document files, leading to an out-of-bounds read and the dereference of an untrusted pointer. A threat actor could craft an Affinity document that, when opened by a user in Affinity, could result in memory corruption or an application crash.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Affinity by Canvato a version that resolves this vulnerability.Fixed in 3.3.1
Event History
Frequently Asked Questions
Who is exposed to this issue?
Users of the Affinity by Canva application running a version before 3.3.1 are exposed if they open a crafted Affinity document. The issue is triggered during parsing of raster image data embedded in the document.
What does an attacker need to exploit it?
An attacker needs to create a malicious Affinity document and persuade a user to open it in the affected application. The supplied severity vector indicates no attacker privileges are required, but user interaction is required.
What should teams do if they cannot update immediately?
Avoid opening Affinity documents from untrusted or unexpected sources until version 3.3.1 can be deployed. The described impact includes application crashes and potential memory corruption.