CVE-2026-15184

Source
https://cve.org/CVERecord?id=CVE-2026-15184
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-15184.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-15184
Downstream
Related
Published
2026-07-09T12:00:17.369Z
Modified
2026-08-12T15:32:46.261950Z
Severity
  • 1.9 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
GNU LibreDWG DWG File dwg.c dwg_next_entity null pointer dereference
Details

A vulnerability was found in GNU LibreDWG up to 0.13.4. The impacted element is the function dwgnextentity of the file src/dwg.c of the component DWG File Handler. Performing a manipulation of the argument next_obj results in null pointer dereference. The attack must be initiated from a local position. The exploit has been made public and could be used. Upgrading to version 0.14 is sufficient to resolve this issue. The patch is named dde45dac3c4d902e4d8fed150a8017b9732019c9. Upgrading the affected component is recommended. Different than CVE-2026-9503.

Database specific
{
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "0.13.0"
                },
                {
                    "last_affected": "0.13.0"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ],
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-404",
        "CWE-476"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/15xxx/CVE-2026-15184.json"
}
References

Affected packages

Git / github.com/libredwg/libredwg

Affected ranges

Type
GIT
Repo
https://github.com/libredwg/libredwg
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0.13.1"
        },
        {
            "last_affected": "0.13.1"
        },
        {
            "introduced": "0.13.2"
        },
        {
            "last_affected": "0.13.2"
        },
        {
            "introduced": "0.13.3"
        },
        {
            "last_affected": "0.13.3"
        },
        {
            "introduced": "0.13.4"
        },
        {
            "last_affected": "0.13.4"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

0.*
0.13.1
0.13.2
0.13.3
0.13.3.7163
0.13.3.7165
0.13.3.7166
0.13.3.7168
0.13.3.7176
0.13.3.7183
0.13.3.7186
0.13.3.7187
0.13.3.7190
0.13.3.7199
0.13.3.7217
0.13.3.7220
0.13.3.7223
0.13.3.7224
0.13.3.7225
0.13.3.7226
0.13.3.7227
0.13.3.7233
0.13.3.7240
0.13.3.7246
0.13.3.7251
0.13.3.7257
0.13.3.7259
0.13.3.7262
0.13.3.7264
0.13.3.7265
0.13.3.7268
0.13.3.7270
0.13.3.7273
0.13.3.7298
0.13.3.7306
0.13.3.7308
0.13.3.7320
0.13.3.7324
0.13.3.7327
0.13.3.7338
0.13.3.7341
0.13.3.7344
0.13.3.7345
0.13.3.7351
0.13.3.7371
0.13.3.7377
0.13.3.7385
0.13.3.7405
0.13.3.7409
0.13.3.7411
0.13.3.7412
0.13.3.7414
0.13.3.7420
0.13.3.7424
0.13.3.7426
0.13.3.7429
0.13.3.7431
0.13.3.7434
0.13.3.7437
0.13.3.7442
0.13.3.7445
0.13.3.7453
0.13.3.7456
0.13.3.7460
0.13.3.7466
0.13.3.7469
0.13.3.7472
0.13.3.7473
0.13.3.7483
0.13.3.7491
0.13.3.7501
0.13.3.7507
0.13.3.7516
0.13.3.7533
0.13.3.7534
0.13.3.7535
0.13.3.7539
0.13.3.7545
0.13.3.7551
0.13.3.7552
0.13.3.7554
0.13.3.7557
0.13.3.7558
0.13.3.7562
0.13.3.7571
0.13.3.7574
0.13.3.7577
0.13.3.7582
0.13.3.7599
0.13.3.7600
0.13.3.7603
0.13.3.7635
0.13.3.7637
0.13.3.7640
0.13.3.7646
0.13.3.7649
0.13.3.7650
0.13.3.7657
0.13.3.7663
0.13.3.7665
0.13.3.7675
0.13.3.7680
0.13.3.7685
0.13.3.7686
0.13.3.7690
0.13.3.7696
0.13.3.7702
0.13.3.7715
0.13.3.7721
0.13.3.7727
0.13.3.7730
0.13.3.7737
0.13.3.7741
0.13.3.7743
0.13.3.7752
0.13.3.7761
0.13.3.7763
0.13.3.7772
0.13.3.7776
0.13.3.7778
0.13.3.7789
0.13.3.7792
0.13.3.7794
0.13.3.7797
0.13.3.7802
0.13.3.7805
0.13.3.7808
0.13.3.7810
0.13.3.7812
0.13.3.7813
0.13.3.7816
0.13.3.7819
0.13.3.7825
0.13.3.7828
0.13.3.7835
0.13.3.7842
0.13.3.7846
0.13.3.7848
0.13.3.7849
0.13.3.7850
0.13.3.7851
0.13.3.7852
0.13.3.7861
0.13.3.7867
0.13.3.7873
0.13.3.7883
0.13.3.7897
0.13.3.7901
0.13.3.7906
0.13.3.7913
0.13.3.7918
0.13.4
0.13.4.7969
0.13.4.7974
0.13.4.7976
0.13.4.7985
0.13.4.7998
0.13.4.8001
0.13.4.8014
0.13.4.8018
0.13.4.8028
0.13.4.8036
0.13.4.8043
0.13.4.8051
0.13.4.8055
0.13.4.8085
0.13.4.8091
0.13.4.8104
0.13.4.8112
0.13.4.8115
0.13.4.8118
0.13.4.8123
0.13.4.8129
0.13.4.8131
0.13.4.8140
0.13.4.8144
0.13.4.8149
0.13.4.8160
0.13.4.8163
0.13.4.8166
0.13.4.8168
0.13.4.8169
0.13.4.8171
0.13.4.8174
0.13.4.8178
0.13.4.8187
0.13.4.8198
0.13.4.8200
0.13.4.8214
0.13.4.8216
0.13.4.8229
0.13.4.8230
0.13.4.8231
0.13.4.8234
0.13.4.8236
0.13.4.8237
0.13.4.8241
0.13.4.8246
0.13.4.8249
0.13.4.8252
0.13.4.8263
0.13.4.8268
0.13.4.8270
0.13.4.8273
0.13.4.8278
0.13.4.8284
0.13.4.8285
0.13.4.8293
0.13.4.8294
0.13.4.8295
0.13.4.8302
0.13.4.8304
0.13.4.8313
0.13.4.8317
0.13.4.8321
0.13.4.8336
0.13.4.8343
0.13.4.8348
0.13.4.8351
0.13.4.8356
0.13.4.8360

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-15184.json"
vanir_signatures
[
    {
        "target": {
            "file": "src/dwg.c"
        },
        "deprecated": false,
        "source": "https://github.com/libredwg/libredwg/commit/dde45dac3c4d902e4d8fed150a8017b9732019c9",
        "id": "CVE-2026-15184-121636fc",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "283908051862068991641318697991292540447",
                "174629125796972352612646642734445381488",
                "305815804209540658282933558469462225609",
                "3443758331641539744134354646641318210"
            ]
        },
        "signature_type": "Line"
    },
    {
        "target": {
            "file": "src/encode.c"
        },
        "deprecated": false,
        "source": "https://github.com/libredwg/libredwg/commit/d9468ae948b8f07a08efa756c19f8916052358c0",
        "id": "CVE-2026-15184-9d8b7cb7",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "49767515012856523006609786846141487675",
                "51767973309089573731138741627418469522",
                "214988644504213162965813640952238262990",
                "244819296756283961456692824590706746832",
                "27844949856869863672095217557809784032",
                "77896253088770974522687231449032865388",
                "109656386444620635452392358778299269116",
                "296031323750994905362176623140475984053",
                "106201200356465986227145837673662370733",
                "30256074524972750250787441305293718266",
                "173369055911681301747166990024197824583",
                "143621292742105292688096803105989929264",
                "65876926228280999514100252927459455022",
                "85392031684084465774002464460570711921",
                "249238180479009043757627070605456909292",
                "195222699048597012469761422123501115447"
            ]
        },
        "signature_type": "Line"
    },
    {
        "target": {
            "file": "examples/dwgfuzz.c"
        },
        "deprecated": false,
        "source": "https://github.com/libredwg/libredwg/commit/d9468ae948b8f07a08efa756c19f8916052358c0",
        "id": "CVE-2026-15184-d1ac7042",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "154512130852018455397856659198690717106",
                "51876481842413898283512797170439118054",
                "174184467050061406361915063095242200094",
                "72521053116087091797231805787808258915",
                "294587100473962440125218262153547687185",
                "291013262779701407238566580163244165335",
                "286715408555221545764630641579777262070",
                "188660135417106434958253696063144996382",
                "251312105046776457484298978991698236668",
                "95784509257409776765300152242340662557",
                "173539188606416070312364628183834824913",
                "249782971859245451613310168160955920048",
                "226235201698424972492719238058069981173"
            ]
        },
        "signature_type": "Line"
    },
    {
        "target": {
            "function": "main",
            "file": "examples/dwgfuzz.c"
        },
        "deprecated": false,
        "source": "https://github.com/libredwg/libredwg/commit/d9468ae948b8f07a08efa756c19f8916052358c0",
        "id": "CVE-2026-15184-d6d3b436",
        "signature_version": "v1",
        "digest": {
            "length": 5110.0,
            "function_hash": "268448865954434003822748246748691671176"
        },
        "signature_type": "Function"
    },
    {
        "target": {
            "function": "dwg_next_entity",
            "file": "src/dwg.c"
        },
        "deprecated": false,
        "source": "https://github.com/libredwg/libredwg/commit/dde45dac3c4d902e4d8fed150a8017b9732019c9",
        "id": "CVE-2026-15184-eb89dfb6",
        "signature_version": "v1",
        "digest": {
            "length": 727.0,
            "function_hash": "194826465361379040313319372703267219534"
        },
        "signature_type": "Function"
    }
]
vanir_signatures_modified
"2026-08-12T15:32:46Z"