GHSA-wq5f-xc86-pv6w: Use After Free

Published Oct 6, 2026
·
Updated

Impact

A memory-related vulnerability has been discovered and fixed in the upstream librsvg dependency. When certain runtime-specific conditions apply, this vulnerability can lead to possible remote code execution (RCE) on glibc-based Linux.

Patches

Using prebuilt binaries provided by sharp?

Most people rely on the prebuilt binaries provided by sharp.

Please upgrade sharp to the latest version, currently 0.35.5, which provides librsvg 2.63.2.

Using a globally-installed librsvg?

Please ensure you are using the latest librsvg 2.63.2.

Workarounds

Add the following to your code to prevent sharp from decoding SVG images. js sharp.block({ operation: ["VipsForeignLoadSvg"] });

To avoid RCE, ensure you are using a node executable binary compiled as a Position Independent Executable (PIE). Most Linux package managers already use this security-hardening feature however be warned that the "official" Node.js binaries do not. 1

Affected Software

1 affected componentFixes available
npm/sharp<0.35.5
0.35.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/sharp to a version that resolves this vulnerability.

    Fixed in 0.35.5
  2. Upgrade

    Upgrade librsvg to a version that resolves this vulnerability.

    Fixed in 2.63.2
  3. Upgrade

    Upgrade sharp to a version that resolves this vulnerability.

    Fixed in 0.35.5
  4. Configuration

    Add sharp.block({ operation: ["VipsForeignLoadSvg"] }) to prevent sharp from decoding SVG images.

    sharp block.operation = VipsForeignLoadSvg
  5. Configuration

    Use a node executable binary compiled as a Position Independent Executable (PIE) to reduce the risk of remote code execution.

    node executable Position Independent Executable (PIE) = enabled

Event History

Oct 6, 2026
Advisory Published
via GitHub·01:43 PM
Data Sourced
via GitHub·01:43 PM
DescriptionWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are most exposed to remote code execution?

The stated RCE risk applies on glibc-based Linux when the runtime-specific conditions are present. The risk is specifically associated with sharp decoding SVG images through its librsvg dependency.

2

What must an attacker be able to do to exploit this issue?

An attacker would need to cause sharp to decode a crafted SVG image. The advisory does not provide further prerequisites or attack paths.

3

Are standard sharp installations affected, and what version fixes them?

Most sharp users rely on its prebuilt binaries and should upgrade sharp to version 0.35.5, which provides librsvg 2.63.2. Installations using a globally installed librsvg should ensure that librsvg is version 2.63.2.

4

What can be done if upgrading cannot happen immediately?

Disable SVG decoding in sharp by adding sharp.block({ operation: ["VipsForeignLoadSvg"] }); to the application. To avoid RCE, use a Node executable compiled as a Position Independent Executable (PIE); the advisory warns that official Node.js binaries do not have this hardening.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203