MEDIUM
memononen
CVE published 2026-09-24
CVE-2026-88367
CVE-2026-88367 is a denial-of-service vulnerability in NanoSVG, caused by incorrect numeric conversion during SVG stroke rasterization. A specially crafted SVG document with an extremely large stroke-width can lead to undefined behavior and process termination. The vulnerability is triggered when a large stroke-width causes floating-point rounding to produce a zero subdivision angle, resulting in infinity [truncated]