CVE-2026-96889
published 2026-09-23CVE-2026-96889: A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate entity declarations, a use-after-free…
PriorityP340high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.13%
2.2th percentile
A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate entity declarations, a use-after-free error can occur. This vulnerability arises because the library incorrectly frees an XML entity that is still in use by the parser. An attacker could potentially exploit this to cause a denial of service or execute arbitrary code.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| code16 | sharp | >= 0 < 0.35.5 | 0.35.5 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
ghsa7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
librsvg: Use-after-free when XML includes have duplicated entities
vendor_redhat·2026-09-23·CVSS 7.8
CVE-2026-96889 [HIGH] CWE-416 librsvg: Use-after-free when XML includes have duplicated entities
librsvg: Use-after-free when XML includes have duplicated entities
A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate entity declarations, a use-after-free error can occur. This vulnerability arises because the library incorrectly frees an XML entity that is still in use by the parser. An attacker could potentially exploit this to cause a denial of service or execute arbitrary code.
Statement: This is an Important use-after-free flaw in librsvg, which could lead to arbitrary code execution or denial of service. The vulnerability occurs when processing a specially crafted SVG document containing nested Xincludes with duplicated XML entity declarations. Exploitation requires user interaction, such as opening a malicious
GHSA
sharp : Vulnerability in librsvg dependency CVE-2026-96889
ghsa·2026-10-06·CVSS 7.8
CVE-2026-96889 [HIGH] CWE-1395 sharp : Vulnerability in librsvg dependency CVE-2026-96889
sharp : Vulnerability in librsvg dependency CVE-2026-96889
### Impact
A memory-related vulnerability has been discovered and fixed in the upstream librsvg dependency. When certain runtime-specific conditions apply, this vulnerability can lead to possible remote code execution (RCE) on glibc-based Linux.
### Patches
#### Using prebuilt binaries provided by sharp?
Most people rely on the prebuilt binaries provided by sharp.
Please upgrade sharp to the latest version, currently 0.35.5, which provides librsvg 2.63.2.
#### Using a globally-installed librsvg?
Please ensure you are using the latest librsvg 2.63.2.
### Workarounds
Add the following to your code to prevent sharp from decoding SVG images.
```js
sharp.block({ operation: ["VipsForeignLoadSvg"] });
```
To avoid RCE, ensure y
VulDB
Red Hat Enterprise Linux librsvg use after free
vuldb·2026-09-23·CVSS 7.8
CVE-2026-96889 [HIGH] Red Hat Enterprise Linux librsvg use after free
A vulnerability described as problematic has been identified in Red Hat Enterprise Linux. This issue affects some unknown processing of the component librsvg. Executing a manipulation can lead to use after free.
The identification of this vulnerability is CVE-2026-96889. The attack can only be executed locally. There is no exploit available.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-96889 librsvg2: Use-after-free when XML includes have duplicated entities [fedora-all]
bugzilla·2026-09-23·CVSS 7.8
CVE-2026-96889 [HIGH] CVE-2026-96889 librsvg2: Use-after-free when XML includes have duplicated entities [fedora-all]
CVE-2026-96889 librsvg2: Use-after-free when XML includes have duplicated entities [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Librsvg uses libxml2, a C library, to parse XML. When librsvg parses
an SVG document which has a nested Xinclude, an XML entity declaration
with a duplicate name as an existing one can cause a use-after-free error.
While libxml2 is expanding an internal entity, a recursive XInclude
can parse another document that declares an entity with the same
name. Both parses use the same `XmlState` entity
map on the librsvg side. `entity_insert()` replaces the first entry, whose `Drop
Bugzilla
CVE-2026-96889 rust-librsvg: Use-after-free when XML includes have duplicated entities [fedora-all]
bugzilla·2026-09-23·CVSS 7.8
CVE-2026-96889 [HIGH] CVE-2026-96889 rust-librsvg: Use-after-free when XML includes have duplicated entities [fedora-all]
CVE-2026-96889 rust-librsvg: Use-after-free when XML includes have duplicated entities [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Librsvg uses libxml2, a C library, to parse XML. When librsvg parses
an SVG document which has a nested Xinclude, an XML entity declaration
with a duplicate name as an existing one can cause a use-after-free error.
While libxml2 is expanding an internal entity, a recursive XInclude
can parse another document that declares an entity with the same
name. Both parses use the same `XmlState` entity
map on the librsvg side. `entity_insert()` replaces the first entry, whose `
Bugzilla
CVE-2026-96889 librsvg: Use-after-free when XML includes have duplicated entities
bugzilla·2026-09-23·CVSS 7.8
CVE-2026-96889 [HIGH] CVE-2026-96889 librsvg: Use-after-free when XML includes have duplicated entities
CVE-2026-96889 librsvg: Use-after-free when XML includes have duplicated entities
Librsvg uses libxml2, a C library, to parse XML. When librsvg parses
an SVG document which has a nested Xinclude, an XML entity declaration
with a duplicate name as an existing one can cause a use-after-free error.
While libxml2 is expanding an internal entity, a recursive XInclude
can parse another document that declares an entity with the same
name. Both parses use the same `XmlState` entity
map on the librsvg side. `entity_insert()` replaces the first entry, whose `Drop`
implementation calls `xmlFreeNode()`. The outer `xmlCtxtParseEntity()`
then keeps using the freed 144-byte `xmlEntity`.
The included parse should not free an entity that the outer parser is still using.
The fix is in commit 8a1b0cd319e
https://access.redhat.com/security/cve/CVE-2026-96889https://bugzilla.redhat.com/show_bug.cgi?id=2539279https://crates.io/crates/librsvghttps://gitlab.gnome.org/GNOME/librsvg/-/work_items/1241https://rustsec.org/advisories/RUSTSEC-2026-0305.htmlhttps://gitlab.gnome.org/GNOME/librsvg/-/work_items/1241
2026-09-23
Published