librsvg
crates.io2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting librsvgpage 1 of 1
- CVE-2015-7558HIGHCVSS 7.5EG 7.5fixed in 2.40.122016-05-20
librsvg before 2.40.12 allows context-dependent attackers to cause a denial of service (infinite loop, stack consumption, and application crash) via cyclic references in an SVG document.
- CVE-2026-96889HIGHCVSS 7.8EG 7.8fixed in 2.57.5, 2.60.3, 2.61.5, 2.62.4 or 2.63.2, by version range2026-09-23
A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate entity declarations, a use-after-free error can occur. This vulnerability arises because the library incorrectly frees…
Check whether librsvg is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for librsvg CVEs against the assets you own.
Book a Demo →