CVE-2026-25920 | sumatrapdfreader SumatraPDF up to 3.5.2 on Windows MOBI HuffDic Decompressor AddCdicData out-of-bounds (GHSA-5mwx-65x7-cffp)
A vulnerability described as problematic has been identified in sumatrapdfreader SumatraPDF up to 3.5.2 on Windows. Affected by this vulnerability is the function AddCdicData of the component MOBI HuffDic Decompressor. Executing a manipulation can lead to out-of-bounds read.
This vulnerability is registered as CVE-2026-25920. It is possible to launch the attack remotely. No exploit is available.
It is best practice to apply a patch to resolve this issue.