OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-88366

HIGH · CVSS 7.5 EPSS 0.34% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability affects the NanoSVG library, specifically in the nsvg__pathArcTo() function, which improperly handles extreme arc radius values in SVG documents. This flaw can lead to the generation of a NaN delta angle during calculations, ultimately causing undefined behavior and potential process termination, resulting in a denial of service. Developers and organizations using NanoSVG for SVG parsing should prioritize addressing this issue to prevent service disruptions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-88366
Severity
HIGH
CVSS
7.5
EPSS
0.34%

Original NVD Description

NanoSVG commit 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__pathArcTo() when parsing SVG arc commands. A specially crafted SVG document containing extreme arc radius values can cause intermediate arc calculations to produce a NaN delta angle. The function subsequently converts this NaN value to int without validating that it is finite and representable, resulting in undefined behavior and process termination, leading to denial of service.