PT-2026-97868 · Canonical · Nanosvg

CVE-2026-88366

·

Published

2026-09-24

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions NanoSVG versions prior to commit 239e102ec
Description An incorrect numeric conversion occurs in the nsvg pathArcTo() function when parsing SVG arc commands. A specially crafted SVG document with extreme arc radius values can cause intermediate calculations to produce a NaN (Not-a-Number) delta angle. The function converts this NaN value to an integer without validating if it is finite or representable, leading to undefined behavior, process termination, and a denial of service.
Recommendations Update NanoSVG to a version containing the fix implemented after commit 239e102ec. As a temporary mitigation, restrict the processing of SVG documents containing extreme arc radius values.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-88366

Affected Products

Nanosvg