Back to database
Schedule36Medium6.5VulnerabilityCVE-2026-88367No patch link observed

CVE-2026-88367 — NanoSVG 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__curveDivs() during SVG stroke rasterization.

Published Sep 24, 2026, 05:17 PM UTCIngested 14d agoSource NVD(cve-db)CVE-2026-88367

Description

NanoSVG 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__curveDivs() during SVG stroke rasterization. A specially crafted SVG document containing an extremely large stroke-width can cause floating-point rounding to produce a zero subdivision angle. The subsequent arc division yields infinity, which is converted to int without range validation, resulting in undefined behavior and process termination, leading to denial of service.

CVSS v3.1 base metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
6.5

Medium severity

Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.

AV

Network

Attack Vector

AC

Low

Attack Complexity

PR

None

Privileges Required

UI

Required

User Interaction

S

Unchanged

Scope

C

None

Confidentiality

I

None

Integrity

A

High

Availability