Vulnerabilities in Affinity by Canva app before 3.3.1 (October 2026 release)
Canva Logo

Trust & Security Portal

Start your security review
View & download sensitive information
ControlK

Canva is an online digital design and publishing platform that enables individuals, teams, and enterprises to create visual content collaboratively. It supports the creation of a wide range of content, including social media posts, presentations, videos, posters, logos, and websites. With over 220 million monthly active users worldwide, trust, privacy, and security are central to how we operate. Learn more about Canva here - https://www.canva.com/about/.

This Trust & Security Portal provides visibility into Canva’s security posture, privacy practices, compliance commitments, and reliability controls. You can also request access to our security documentation and audit reports through the portal.

  • Expedia Group
  • Salesforce
  • T-Mobile
  • Stripe
  • Airbnb
  • HubSpot

Documents

LEGALCyber Insurance

Subprocessors

Trust & Security Portal Updates

Vulnerabilities in Affinity by Canva app before 3.3.1 (October 2026 release)

Vulnerabilities

Security Bulletin

CVE-2026-96393

CVE: CVE-2026-96393
Severity: Low
CVSS: 3.6 – CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L

Affected Products and Versions

  • Affinity by Canva app before 3.3.1

Details

The Affinity by Canva app before 3.3.1 (October 2026 release) did not perform adequate bounds checking when parsing Affinity document files, leading to an out-of-bounds pointer dereference. A threat actor could craft an Affinity document that, when opened by a user in Affinity, could result in an application crash.

Remediation Advice

Canva recommends users upgrade to the latest version of the Affinity application for their platform.

Timeline

  • Sep 17 2026 – Findings reported to Canva
  • Sep 28 2026 – Vulnerability triaged by Canva and accepted
  • Oct 8 2026 – Fix released

Acknowledgements

This vulnerability was submitted to Canva by Xusheng Li.

CVE-2026-96394

CVE: CVE-2026-96394
Severity: Low
CVSS: 2.9 – CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected Products and Versions

  • Affinity by Canva app for macOS before 3.3.1

Details

The Affinity by Canva application for macOS before 3.3.1 (October 2026 release) did not validate image dimensions against the size of the pixel data when generating QuickLook thumbnails and previews of Affinity document files, leading to an out-of-bounds heap read. A threat actor could craft an Affinity document that, when displayed or previewed by a user in Finder, could disclose the contents of adjacent heap memory in the rendered thumbnail or preview image, or cause the thumbnail or preview extension to crash.

Remediation Advice

Canva recommends users upgrade to the latest version of the Affinity application for macOS.

Timeline

  • Sep 17 2026 – Findings reported to Canva
  • Sep 22 2026 – Vulnerability triaged by Canva and accepted
  • Oct 8 2026 – Fix released

Acknowledgements

This vulnerability was submitted to Canva by Xusheng Li.

CVE-2026-96395

CVE: CVE-2026-96395
Severity: Low
CVSS: 3.6 – CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L

Affected Products and Versions

  • Affinity by Canva app for macOS before 3.3.1

Details

The Affinity by Canva app for macOS before 3.3.1 (October 2026 release) did not perform adequate bounds checking when generating QuickLook thumbnails and previews of Affinity document files, leading to an out-of-bounds heap read. A threat actor could craft an Affinity document that, when displayed or previewed by a user in Finder, could disclose the contents of adjacent heap memory, including memory addresses, in the rendered thumbnail or preview image.

Remediation Advice

Canva recommends users upgrade to the latest version of the Affinity application for macOS.

Timeline

  • Sep 17 2026 – Findings reported to Canva
  • Sep 22 2026 – Vulnerability triaged by Canva and accepted
  • Oct 8 2026 – Fix released

Acknowledgements

This vulnerability was submitted to Canva by Xusheng Li.

CVE-2026-96396

CVE: CVE-2026-96396
Severity: Medium
CVSS: 4.9 – CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

Affected Products and Versions

  • Affinity by Canva app for macOS before 3.3.1

Details

The Affinity by Canva application for macOS before 3.3.1 (October 2026 release) did not safely calculate the size of an image buffer when generating QuickLook thumbnails and previews of Affinity document files, leading to an integer overflow and a heap-based buffer overflow. A threat actor could craft an Affinity document that, when displayed or previewed by a user in Finder, could corrupt heap memory and cause the thumbnail or preview extension to crash.

Remediation Advice

Canva recommends users upgrade to the latest version of the Affinity application for macOS.

Timeline

  • Sep 17 2026 – Findings reported to Canva
  • Sep 22 2026 – Vulnerability triaged by Canva and accepted
  • Oct 8 2026 – Fix released

Acknowledgements

This vulnerability was submitted to Canva by Xusheng Li.

CVE-2026-103220

CVE: CVE-2026-103220
Severity: Medium
CVSS: 4.5 – CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L

Affected Products and Versions

  • Affinity by Canva app before 3.3.1

Details

The Affinity by Canva application before 3.3.1 (October 2026 release) did not perform adequate bounds checking when parsing raster image data in Affinity document files, leading to an out-of-bounds read and the dereference of an untrusted pointer. A threat actor could craft an Affinity document that, when opened by a user in Affinity, could result in memory corruption or an application crash.

Remediation Advice

Canva recommends users upgrade to the latest version of the Affinity application for their platform.

Timeline

  • Sep 17 2026 – Findings reported to Canva
  • Sep 23 2026 – Vulnerability triaged by Canva and accepted
  • Oct 8 2026 – Fix released

Acknowledgements

This vulnerability was submitted to Canva by Xusheng Li.

CVE-2026-101130

CVE: CVE-2026-101130
Severity: Low
CVSS: 3.6 – CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L

Affected Products and Versions

  • Affinity by Canva app before 3.3.1

Details

The Affinity by Canva application before 3.3.1 (October 2026 release) did not perform adequate bounds checking when parsing arrays of strings in Affinity document files, leading to a heap buffer over-read. A threat actor could craft an Affinity document that, when opened by a user in Affinity, could disclose the contents of adjacent heap memory in the document's text or result in an application crash.

Remediation Advice

Canva recommends users upgrade to the latest version of the Affinity application for their platform.

Timeline

  • Sep 17 2026 – Findings reported to Canva
  • Sep 28 2026 – Vulnerability triaged by Canva and accepted
  • Oct 8 2026 – Fix released

Acknowledgements

This vulnerability was submitted to Canva by Xusheng Li.

CVE-2026-101094

CVE: CVE-2026-101094
Severity: Low
CVSS: 3.6 – CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L

Affected Products and Versions

  • Affinity by Canva app before 3.3.1

Details

The Affinity by Canva application before 3.3.1 (October 2026 release) did not correctly handle incomplete UTF-8 character sequences when parsing text in Affinity document files, leading to a heap buffer over-read. A threat actor could craft an Affinity document that, when opened by a user in Affinity, could disclose the contents of adjacent heap memory in the document's text or result in an application crash.

Remediation Advice

Canva recommends users upgrade to the latest version of the Affinity application for their platform.

Timeline

  • Sep 17 2026 – Findings reported to Canva
  • Sep 28 2026 – Vulnerability triaged by Canva and accepted
  • Oct 8 2026 – Fix released

Acknowledgements

This vulnerability was submitted to Canva by Xusheng Li.

CVE-2026-90860

Vulnerabilities

Security Bulletin

CVE: CVE-2026-90860
Severity: High
CVSS: 7.1 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
Affected Products and Versions:

  • Canva Mobile App for HarmonyOS before v1.15.1

Details

The Canva Mobile App for HarmonyOS before v1.15.1 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user's session.

Remediation Advice

Canva recommends users upgrade to the latest version of the Canva HarmonyOS App.

Timeline

2 September 2026 - Vulnerability identified by Canva
16 September 2026 - Fix released

Acknowledgements

This vulnerability was discovered by Wing Cheng and Tin Duong of Canva's Security Group.

CVE-2026-92839

Vulnerabilities

Security Bulletin

CVE-2026-92839

CVE: CVE-2026-92839
Severity: Medium
CVSS: 4.3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Affected Products and Versions:

  • Canva Desktop before v1.125.0

Details

Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin content under the user's session.

Remediation Advice

Canva recommends users upgrade to the latest version of the Canva Desktop Application.

Timeline

  • 25 July 2026 - Reported to Canva through our bug bounty program
  • 7 August 2026 - Vulnerability triaged by Canva and accepted
  • 9 September 2026 - Fix released

Acknowledgements

This vulnerability was submitted to Canva's Bug Bounty Program by spoderx555.

CVE-2026-81546

Vulnerabilities

Security Bulletin

CVE-2026-81546

Published Date: 17 September 2026
CVE: CVE-2026-81546
Severity: High
CVSS: 7.7 - CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products and Versions:

  • Affinity by Canva app before 3.3.0

Details

The Affinity by Canva application before 3.3.0 (September 2026 release) did not perform adequate bounds checking when parsing Affinity document files, leading to a stack-based buffer overflow. A threat actor could craft an Affinity document that, when opened by a user in Affinity, could result in arbitrary code execution.

Remediation Advice

Canva recommends users upgrade to the latest version of the Affinity application for their platform.

Timeline

  • 24 July 2026 - Vulnerability identified by Canva
  • 3 September 2026 - Vulnerability remediated
  • 16 September 2026 - Fix released
  • 17 September 2026 - Public Disclosure

Acknowledgements

This vulnerability was discovered by Angus Cornall of Canva's Security Group.

Vulnerabilities in Canva Android App before 2.376.0

Vulnerabilities

Security Bulletin

CVE-2026-85085

Published Date: 4 September 2026
CVE: CVE-2026-85085
Severity: Critical
CVSS: 9.6 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L

Affected Products and Versions:

  • Canva Mobile App for Android before 2.376.0

Details

The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with Canva using the user's session.

Remediation Advice

Canva recommends users upgrade to the latest version of the Canva Android app.

Timeline

  • 5 August 2026 — Reported to Canva through our bug bounty program
  • 20 August 2026 — Vulnerability triaged by Canva and accepted
  • 3 September 2026 — Fix released
  • 4 September 2026 — Public Disclosure

Acknowledgements

This vulnerability was submitted to Canva's Bug Bounty Program by vldevadath06.

CVE-2026-85094

Published Date: 4 September 2026
CVE: CVE-2026-85094
Severity: High
CVSS: 8.8 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products and Versions:

  • Canva Mobile App for Android before 2.376.0

Details

The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user's session.

Remediation Advice

Canva recommends users upgrade to the latest version of the Canva Android App.

Timeline

  • 5 August 2026 — Reported to Canva through our bug bounty program
  • 20 August 2026 — Vulnerability triaged by Canva and accepted
  • 3 September 2026 — Fix released
  • 4 September 2026 — Public Disclosure

Acknowledgements

This vulnerability was submitted to Canva's bug bounty Program by hakupiku.