PT-2026-97868 · Canonical · Nanosvg
CVE-2026-88366
·
Published
2026-09-24
·
Updated
2026-09-24
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
NanoSVG versions prior to commit 239e102ec
Description
An incorrect numeric conversion occurs in the
nsvg pathArcTo() function when parsing SVG arc commands. A specially crafted SVG document with extreme arc radius values can cause intermediate calculations to produce a NaN (Not-a-Number) delta angle. The function converts this NaN value to an integer without validating if it is finite or representable, leading to undefined behavior, process termination, and a denial of service.Recommendations
Update NanoSVG to a version containing the fix implemented after commit 239e102ec.
As a temporary mitigation, restrict the processing of SVG documents containing extreme arc radius values.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nanosvg