librsvg and NanoSVG flaws trigger without JavaScript
RustSec disclosed a use-after-free in librsvg (CVE-2026-96889) involving nested XML entities, fixed in 2.63.2 and 2.62.4. NanoSVG (CVE-2026-88366) produces NaN from extreme arc radii, causing undefined behavior and potential denial of service. Neither flaw requires JavaScript.
- CVE-2026-96889 in librsvg: use-after-free with duplicate XML entities
- Fixes shipped in librsvg 2.63.2 and 2.62.4 on September 23, 2026
- CVE-2026-88366 in NanoSVG: NaN from arc radii enables denial of service
- Stripping scripts does not make SVG rendering safe
Read next
Security