OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-96889

HIGH · CVSS 7.8 EPSS 0.13% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

A use-after-free vulnerability in librsvg allows for the improper handling of nested XML inclusions with duplicate entity declarations, leading to potential denial of service or arbitrary code execution. Affected products utilizing this library should prioritize patching, especially those in environments where SVG documents are processed, to mitigate the risk of exploitation. Organizations relying on librsvg for rendering or processing SVG files should take immediate action to address this high-severity flaw.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-96889
Severity
HIGH
CVSS
7.8
EPSS
0.13%

Original NVD Description

A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate entity declarations, a use-after-free error can occur. This vulnerability arises because the library incorrectly frees an XML entity that is still in use by the parser. An attacker could potentially exploit this to cause a denial of service or execute arbitrary code.