CVE-2026-96393: Low severity Canva Affinity vulnerability
The Affinity by Canva app before 3.3.1 (October 2026 release) did not perform adequate bounds checking when parsing Affinity document files, leading to an out-of-bounds pointer dereference. A threat actor could craft an Affinity document that, when opened by a user in Affinity, could result in an application crash.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Affinity by Canvato a version that resolves this vulnerability.Fixed in 3.3.1
Event History
Frequently Asked Questions
What must an attacker do to trigger this issue?
An attacker must craft a malicious Affinity document and get a user to open it in Affinity. Exploitation requires local access conditions, high attack complexity, and user interaction.
What impact is documented if the issue is exploited?
Opening the crafted document can cause an out-of-bounds pointer dereference and crash the application. The provided severity vector indicates low integrity and availability impact, with no confidentiality impact.
Which versions should be remediated?
Affinity versions before 3.3.1 are affected. Update to version 3.3.1 or later, identified as the October 2026 release.