Librsvg: use-after-free when xml includes have duplicated entities
Published Sep 23, 2026
7.8
HIGHCVSS 3.1
EPSS 0.13%
Description
A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate entity declarations, a use-after-free error can occur. This vulnerability arises because the library incorrectly frees an XML entity that is still in use by the parser. An attacker could potentially exploit this to cause a denial of service or execute arbitrary code.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 7 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 8 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 9 | affected |
|
No data.
No data.
Red Hat Enterprise Linux 10
glycin-loaders
Affected
Red Hat Enterprise Linux 10
librsvg2
Affected
Red Hat Enterprise Linux 6
librsvg2
Out of support scope
Red Hat Enterprise Linux 7
librsvg2
Affected
Red Hat Enterprise Linux 8
librsvg2
Affected
Red Hat Enterprise Linux 9
librsvg2
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | glycin-loaders | Affected | n/a |
| Red Hat Enterprise Linux 10 | librsvg2 | Affected | n/a |
| Red Hat Enterprise Linux 6 | librsvg2 | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | librsvg2 | Affected | n/a |
| Red Hat Enterprise Linux 8 | librsvg2 | Affected | n/a |
| Red Hat Enterprise Linux 9 | librsvg2 | Affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Red Hat statement
This is an Important use-after-free flaw in librsvg, which could lead to arbitrary code execution or denial of service. The vulnerability occurs when processing a specially crafted SVG document containing nested Xincludes with duplicated XML entity declarations. Exploitation requires user interaction, such as opening a malicious SVG file. The issue has been fixed upstream in version 2.63.1.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Sep 25, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
Percentile over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
References (7)
- https://access.redhat.com/security/cve/CVE-2026-96889 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2539279 issue-trackingx_refsource_REDHATIssue Tracking
- https://crates.io/crates/librsvg
- https://gitlab.gnome.org/GNOME/librsvg/-/work_items/1241 exploit
- https://nvd.nist.gov/vuln/detail/CVE-2026-96889
- https://rustsec.org/advisories/RUSTSEC-2026-0305.html
- https://www.cve.org/CVERecord?id=CVE-2026-96889
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-96889 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2539279 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://crates.io/crates/librsvg | ||
| https://gitlab.gnome.org/GNOME/librsvg/-/work_items/1241 | exploit | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-96889 | ||
| https://rustsec.org/advisories/RUSTSEC-2026-0305.html | ||
| https://www.cve.org/CVERecord?id=CVE-2026-96889 |
Change history (0)
No recorded changes yet.