CVE-2026-24806: Quick-Media Batik Codec FIX package has Code Injection vulnerability
(updated )
Improper Control of Generation of Code (‘Code Injection’) vulnerability in liuyueyi quick-media (plugins/svg-plugin/batik-codec-fix/src/main/java/org/apache/batik/ext/awt/image/codec/png modules). This vulnerability is associated with program files PNGImageEncoder.Java.
This issue affects all quick-media versions. A patch is available: e52fcee
References
Code Behaviors & Features
Detect and mitigate CVE-2026-24806 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →