CVE-2026-88367 — NanoSVG 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__curveDivs() during SVG stroke rasterization.
Description
NanoSVG 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__curveDivs() during SVG stroke rasterization. A specially crafted SVG document containing an extremely large stroke-width can cause floating-point rounding to produce a zero subdivision angle. The subsequent arc division yields infinity, which is converted to int without range validation, resulting in undefined behavior and process termination, leading to denial of service.
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HMedium severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
PR
None
Privileges Required
UI
Required
User Interaction
S
Unchanged
Scope
C
None
Confidentiality
I
None
Integrity
A
High
Availability
References
Related threats
same CWE or vendorCVE-2026-106432 — The BSON encoder in the MongoDB PHP Driver converts a string length to a 32-bit value without validation.
CVE-2026-106432 · 3h ago
CVE-2026-107224 — Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets.
CVE-2026-107224 · 1d ago
CVE-2026-47539 — NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an incorrect numeric conv…
CVE-2026-47539 · 8d ago
CVE-2026-47508 — NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an incorrect conversion…
CVE-2026-47508 · 8d ago
CVE-2026-98049 — In the Linux kernel, the following vulnerability has been resolved: bpf: zero extend the result of an arena 32-bit cmpxchg bpf_convert_ctx_access…
CVE-2026-98049 · 14d ago
CVE-2026-88387 — LibRaw 0.22.0 contains an incorrect numeric conversion vulnerability in LibRaw::parse_tiff_ifd() when processing TIFF tag 0x00fe (NewSubfileType).
CVE-2026-88387 · 14d ago