JLSEC-2026-511

Source
https://github.com/JuliaLang/SecurityAdvisories.jl/blob/main/advisories/published/2026/JLSEC-2026-511.md
Import Source
https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-511.json
JSON Data
https://api.osv.dev/v1/vulns/JLSEC-2026-511
Upstream
Published
2026-05-19T01:34:38.069Z
Modified
2026-05-19T01:45:08.562386Z
Summary
[none]
Details

In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially.

Database specific
{
    "license": "CC-BY-4.0",
    "sources": [
        {
            "imported": "2026-05-19T00:57:41.780Z",
            "html_url": "https://nvd.nist.gov/vuln/detail/CVE-2019-20446",
            "database_specific": {
                "status": "Modified"
            },
            "id": "CVE-2019-20446",
            "published": "2020-02-02T14:15:10.523Z",
            "modified": "2024-11-21T04:38:30.303Z",
            "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2019-20446"
        }
    ]
}
References

Affected packages

Julia / Librsvg_jll

Package

Name
Librsvg_jll
Purl
pkg:julia/Librsvg_jll?uuid=925c91fb-5dd6-59dd-8e8c-345e74382d89

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.52.4+0

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-511.json"