The Affinity by Canva application before 3.3.0 (September 2026 release) did not perform adequate bounds checking when parsing Affinity document files leading to a stack-based buffer overflow. A threat actor could craft a Affinity document that when opened by a user in Affinity could result in arbitrary code execution.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 17 Sep 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Affinity by Canva application before 3.3.0 (September 2026 release) did not perform adequate bounds checking when parsing Affinity document files leading to a stack-based buffer overflow. A threat actor could craft a Affinity document that when opened by a user in Affinity could result in arbitrary code execution. | |
| First Time appeared |
Canva
Canva affinity |
|
| Weaknesses | CWE-121 | |
| CPEs | cpe:2.3:a:canva:affinity:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Canva
Canva affinity |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Canva
Published:
Updated: 2026-09-17T01:39:59.447Z
Reserved: 2026-08-27T00:19:24.496Z
Link: CVE-2026-81546
No data.
Status : Received
Published: 2026-09-17T02:16:27.537
Modified: 2026-09-17T02:16:27.537
Link: CVE-2026-81546
No data.
OpenCVE Enrichment
No data.
Weaknesses