CVE-2026-45729
MEDIUMThor Vector Graphics < 1.0.5 - Denial of Service via Null Pointer Dereference in SvgLoader
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2026-45729. PoCs published by yeahhbean.
AI-analyzed exploit summary Detailed technical analysis of CVE-2026-45729, a NULL pointer dereference in ThorVG's SVG parser triggered by a 6-byte malformed SVG input. The writeup includes root cause analysis, fuzzing setup, patch diff, and exploitability context for both standard Linux (DoS) and MMU-less embedded targets.
Description
Thor Vector Graphics (ThorVG) is a production-ready vector graphics engine. Prior to version 1.0.5, a null pointer dereference in SvgLoader::run() allows any caller that passes untrusted SVG data to Picture::load() to crash the process with a 6-byte payload. This issue has been patched in version 1.0.5.
Exploits (1)
Detailed technical analysis of CVE-2026-45729, a NULL pointer dereference in ThorVG's SVG parser triggered by a 6-byte malformed SVG input. The writeup includes root cause analysis, fuzzing setup, patch diff, and exploitability context for both standard Linux (DoS) and MMU-less embedded targets.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L