PT-2026-45537 · Debian+1 · Thorvg

Yeahhbean

·

Published

2026-06-01

·

Updated

2026-06-01

·

CVE-2026-45729

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Thor Vector Graphics (ThorVG) versions prior to 1.0.5
Description A null pointer dereference occurs in the SvgLoader::run() function. This allows a caller to crash the process using a 6-byte payload by passing untrusted SVG data to the Picture::load() function.
Recommendations Update to version 1.0.5.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45729

Affected Products

Thorvg