Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 09 Oct 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 09 Oct 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Out‑of‑Bounds Pointer Dereference in Affinity by Canva Leads to Application Crash |
Fri, 09 Oct 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Affinity by Canva app before 3.3.1 (October 2026 release) did not perform adequate bounds checking when parsing Affinity document files, leading to an out-of-bounds pointer dereference. A threat actor could craft an Affinity document that, when opened by a user in Affinity, could result in an application crash. | |
| First Time appeared |
Canva
Canva affinity |
|
| Weaknesses | CWE-822 | |
| CPEs | cpe:2.3:a:canva:affinity:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Canva
Canva affinity |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Canva
Published:
Updated: 2026-10-09T16:47:27.904Z
Reserved: 2026-09-23T01:52:48.274Z
Link: CVE-2026-96393
Updated: 2026-10-09T16:15:38.136Z
Status : Awaiting Analysis
Published: 2026-10-09T13:17:12.673
Modified: 2026-10-09T17:16:51.083
Link: CVE-2026-96393
No data.
OpenCVE Enrichment
Updated: 2026-10-09T13:30:05Z
