chiprook
← Security
SecuritySeptember 25, 2026, 21:37

librsvg and NanoSVG flaws trigger without JavaScript

RustSec disclosed a use-after-free in librsvg (CVE-2026-96889) involving nested XML entities, fixed in 2.63.2 and 2.62.4. NanoSVG (CVE-2026-88366) produces NaN from extreme arc radii, causing undefined behavior and potential denial of service. Neither flaw requires JavaScript.

librsvg and NanoSVG flaws trigger without JavaScript
#Librsvg#NanoSVG
Read next
Security

OnePlus flaws let installed apps gain root without permissions

Security

Malicious JavaScript evaded VirusTotal in seven of eight storefront attacks

Security

Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day

Software

Tesla FSD v14.3.9 Bug Triggers False Camera Cleaning Alerts