Skip to content
CanvaCVE-2026-85094

The Canva Android App before 2.376.0 did not restrict the headers returned to...

High8.8CVE-2026-85094 · Published Sep 4, 2026 · updated Sep 8, 2026

The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.

Canva advisory

Affected versions

PackageAffectedFixed in
Canva
Product
< 2.376.02.376.0
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-212

More Canva advisories

All Canva
Advisory
The Canva Mobile App for HarmonyOS before v1.15.1 did not restrict the headers...
High7.1Sep 21
Canva Desktop before v1.125.0 performed double decoding in the deeplink handler
Medium4.3Sep 17
Canva Affinity: stack buffer overflow
High7.7Sep 17
Canva: unverified channel source
Critical9.6Sep 4

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.