CVE-2026-9503
published 2026-05-25CVE-2026-9503: A security flaw has been discovered in GNU LibreDWG up to 0.14. This impacts the function dwg_next_entity of the file src/decode.c of the component DWG File…
PriorityP412low3.3CVSS 3.1
AVLACLPRLUINSUCNINAL
EPSS
0.14%
4.0th percentile
A security flaw has been discovered in GNU LibreDWG up to 0.14. This impacts the function dwg_next_entity of the file src/decode.c of the component DWG File Handler. The manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The patch is identified as 8f03865f37f5d4ffd616fef802acc980be54d300. Upgrading the affected component is advised.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | libredwg | — | — |
| gnu | libredwg | — | — |
| gnu | libredwg | — | — |
| gnu | libredwg | — | — |
| gnu | libredwg | — | — |
| gnu | libredwg | — | — |
| gnu | libredwg | — | — |
| gnu | libredwg | — | — |
| gnu | libredwg | — | — |
| gnu | libredwg | — | — |
| gnu | libredwg | — | — |
| gnu | libredwg | — | — |
| gnu | libredwg | — | — |
| gnu | libredwg | — | — |
| gnu | libredwg | — | — |
| gnu | libredwg | — | — |
| gnu | libredwg | — | — |
| gnu | libredwg | — | — |
| gnu | libredwg | — | — |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
nvdv4.01.9LOWCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.01.7LOWAV:L/AC:L/Au:S/C:N/I:N/A:P
cvelistv5v4.04.8MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A vulnerability was found in GNU LibreDWG up to 0.13.4.
ghsa_unreviewed·2026-07-09·CVSS 3.3
CVE-2026-15184 [LOW] CWE-404 A vulnerability was found in GNU LibreDWG up to 0.13.4.
A vulnerability was found in GNU LibreDWG up to 0.13.4. The impacted element is the function dwg_next_entity of the file src/dwg.c of the component DWG File Handler. Performing a manipulation of the argument next_obj results in null pointer dereference. The attack must be initiated from a local position. The exploit has been made public and could be used. Upgrading to version 0.14 is sufficient to resolve this issue. The patch is named dde45dac3c4d902e4d8fed150a8017b9732019c9. Upgrading the affected component is recommended. Different than CVE-2026-9503.
GHSA
GHSA-q6j5-wxg6-4vrv: A security flaw has been discovered in GNU LibreDWG up to 0
ghsa_unreviewed·2026-05-26
CVE-2026-9503 [LOW] CWE-404 GHSA-q6j5-wxg6-4vrv: A security flaw has been discovered in GNU LibreDWG up to 0
A security flaw has been discovered in GNU LibreDWG up to 0.14. This impacts the function dwg_next_entity of the file src/decode.c of the component DWG File Handler. The manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The patch is identified as 8f03865f37f5d4ffd616fef802acc980be54d300. Upgrading the affected component is advised.
VulDB
GNU LibreDWG up to 0.14 DWG File src/decode.c dwg_next_entity null pointer dereference (Issue 1245 / EUVD-2026-31741)
vuldb·2026-05-25
CVE-2026-9503 [LOW] GNU LibreDWG up to 0.14 DWG File src/decode.c dwg_next_entity null pointer dereference (Issue 1245 / EUVD-2026-31741)
A vulnerability classified as problematic was found in GNU LibreDWG up to 0.14. This impacts the function dwg_next_entity of the file src/decode.c of the component DWG File Handler. The manipulation results in null pointer dereference.
This vulnerability is cataloged as CVE-2026-9503. The attack must be initiated from a local position. Furthermore, there is an exploit available.
Upgrading the affected component is advised.
CVEList
GNU LibreDWG DWG File decode.c dwg_next_entity null pointer dereference
cvelistv5·2026-05-25·CVSS 4.8
CVE-2026-9503 [MEDIUM] CWE-476 GNU LibreDWG DWG File decode.c dwg_next_entity null pointer dereference
GNU LibreDWG DWG File decode.c dwg_next_entity null pointer dereference
A security flaw has been discovered in GNU LibreDWG up to 0.14. This impacts the function dwg_next_entity of the file src/decode.c of the component DWG File Handler. The manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The patch is identified as 8f03865f37f5d4ffd616fef802acc980be54d300. Upgrading the affected component is advised.
Timeline: 2026-05-25: Advisory disclosed; 2026-05-25: VulDB entry created; 2026-05-25: VulDB entry last update
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/HackC0der/CVE-Repos/blob/main/libredwg/libredwg_6d6a339_heap_oob_write_read_2004_compressed_section.dwghttps://github.com/LibreDWG/libredwg/commit/8f03865f37f5d4ffd616fef802acc980be54d300https://github.com/LibreDWG/libredwg/issues/1245https://vuldb.com/submit/814260https://vuldb.com/vuln/365485https://vuldb.com/vuln/365485/ctihttps://www.gnu.org/
2026-05-25
Published