An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.
References
| Link | Resource |
|---|---|
| https://talosintelligence.com/vulnerability_reports/TALOS-2025-2298 | Exploit Third Party Advisory |
| https://trust.canva.com/?tcuUid=1f728b0d-17f3-4c9c-97e9-6662b769eb62 | Vendor Advisory |
| https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2298 | Exploit Third Party Advisory |
Configurations
History
19 Mar 2026, 12:24
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:canva:affinity:*:*:*:*:*:windows:*:* | |
| First Time |
Canva
Canva affinity |
|
| References | () https://talosintelligence.com/vulnerability_reports/TALOS-2025-2298 - Exploit, Third Party Advisory | |
| References | () https://trust.canva.com/?tcuUid=1f728b0d-17f3-4c9c-97e9-6662b769eb62 - Vendor Advisory | |
| References | () https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2298 - Exploit, Third Party Advisory |
18 Mar 2026, 14:52
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
17 Mar 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
17 Mar 2026, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-17 19:15
Updated : 2026-03-19 12:24
NVD link : CVE-2025-62500
Mitre link : CVE-2025-62500
CVE.ORG link : CVE-2025-62500
JSON object : View
Products Affected
canva
- affinity
CWE
CWE-125
Out-of-bounds Read
