Description
An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.
Published: 2026-03-17
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Information Disclosure via Out-of-Bounds Read
Action: Apply Patch
AI Analysis

Impact

An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By supplying a specially crafted EMF file, an attacker can trigger the application to read beyond the boundaries of a buffer, potentially exposing confidential data. The weakness is mapped to CWE-125, which denotes an array index error leading to memory corruption.

Affected Systems

The vulnerability affects Canva Affinity running on Windows platforms. The CPE data (cpe:2.3:a:canva:affinity:*:*:*:*:*:windows:*:*) indicates the product but does not specify individual versions, meaning that all current releases of Canva Affinity on Windows could be impacted unless a vendor patch has already addressed the flaw.

Risk and Exploitability

The CVSS base score of 6.1 places this issue in the moderate severity range. The EPSS score of less than 1% suggests a low likelihood of exploitation, and the vulnerability is not currently listed in the CISA KEV catalog. Exploitation requires a malicious EMF file to be opened by the target, implying a local or user‑initiated attack vector; no remote network entry point is defined in the description.

Generated by OpenCVE AI on March 19, 2026 at 13:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Canva Affinity official support or website for an update that addresses this vulnerability.
  • Update Canva Affinity to the latest patched version as soon as it becomes available.
  • If no patch is available, avoid opening untrusted EMF files and consider disabling EMF file support in the application if an option exists.
  • Implement email and file‑attachment filtering to block or quarantine suspicious image files.
  • Monitor system logs for crashes or anomalous memory access patterns that could indicate exploitation attempts.

Generated by OpenCVE AI on March 19, 2026 at 13:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 24 Mar 2026 13:30:00 +0000

Type Values Removed Values Added
Title Canva Affinity Out-of-Bounds Read via EMF File Leading to Sensitive Information Disclosure

Thu, 19 Mar 2026 12:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:canva:affinity:*:*:*:*:*:windows:*:*

Wed, 18 Mar 2026 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:canva:affinity:-:*:*:*:*:windows:*:*

Wed, 18 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 17 Mar 2026 21:30:00 +0000


Tue, 17 Mar 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Canva
Canva affinity
CPEs cpe:2.3:a:canva:affinity:-:*:*:*:*:windows:*:*
Vendors & Products Canva
Canva affinity

Tue, 17 Mar 2026 19:00:00 +0000

Type Values Removed Values Added
Description An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: talos

Published:

Updated: 2026-03-18T17:00:25.597Z

Reserved: 2026-01-14T15:54:58.484Z

Link: CVE-2026-22882

cve-icon Vulnrichment

Updated: 2026-03-17T20:11:39.506Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-17T19:16:00.780

Modified: 2026-03-19T12:06:30.380

Link: CVE-2026-22882

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-24T10:48:52Z

Weaknesses