Report: CVE-2026-29112 - @dicebear/converter vulnerable to ncontrolled memory allocation via crafted SVG ...

Report: CVE-2026-29112 - @dicebear/converter vulnerable to ncontrolled memory allocation via crafted SVG ...

CVE ID :CVE-2026-29112 Published : March 18, 2026, 4:17 a.m. | 23 minutes ago Description :DiceBear is an avatar library for designers and developers. Prior to version 9.4.0, the `ensureSize()` function in `@dicebear/converter` read the `width` and `height` attributes from the input SVG to determine the output canvas size for rasterization (PNG, JPEG, WebP, AVIF). An attacker who can supply a crafted SVG with extremely large dimensions (e.g. `width=

CVE Details

Published
March 18, 2026