GHSA-wq5f-xc86-pv6w: sharp : Vulnerability in librsvg dependency CVE-2026-96889
A memory-related vulnerability has been discovered and fixed in the upstream librsvg dependency. When certain runtime-specific conditions apply, this vulnerability can lead to possible remote code execution (RCE) on glibc-based Linux.
References
- github.com/advisories/GHSA-wq5f-xc86-pv6w
- github.com/lovell/sharp/commit/96de105d9d36ab04c76c2b78b97255171630d236
- github.com/lovell/sharp/releases/tag/v0.35.5
- github.com/lovell/sharp/security/advisories/GHSA-wq5f-xc86-pv6w
- gitlab.gnome.org/GNOME/librsvg/-/work_items/1241
- www.cve.org/CVERecord?id=CVE-2026-96889
Code Behaviors & Features
Detect and mitigate GHSA-wq5f-xc86-pv6w with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →