CVE-2026-16781: SVG File Parsing Stack Exhaustion Vulnerability in Autodesk 3ds Max
A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can trigger an Uncontrolled Recursion vulnerability. A malicious actor may leverage this vulnerability to cause the application to terminate unexpectedly, resulting in a denial-of-service.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Users of Autodesk 3ds Max who parse an SVG file are exposed. Exploitation requires local access and user interaction, such as opening or otherwise processing a maliciously crafted SVG through the application.
What is the impact if exploitation succeeds?
The crafted SVG can trigger uncontrolled recursion and exhaust the stack, causing Autodesk 3ds Max to terminate unexpectedly. The stated impact is denial of service; no confidentiality or integrity impact is indicated.
What can be done if patching is not immediately possible?
Avoid opening or parsing SVG files from untrusted sources in Autodesk 3ds Max. Because exploitation depends on a malicious SVG being processed, restricting SVG intake can reduce exposure until an update is available.