CVE-2025-10728
A vulnerability exists in a module that handles SVG files. If a file contains a specific element called a <pattern>, the module may attempt to render it repeatedly, causing a stack overflow.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Users or systems utilizing the specific module that renders SVG files containing <pattern> elements.
Real-world impact
An attacker could provide a specially crafted SVG file that causes the system to crash, resulting in a denial-of-service (DoS) condition.
Why this severity
The critical score reflects the high impact on availability, as an attacker can crash the service by providing a malicious file.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Oct 3, 2025 · Oct 3, 2025PublishedDisclosed and added to the National Vulnerability Database.
- Jul 29, 2026 · 7d agoAdvisory updatedThe NVD record was last revised.