Update dependency sharp to v0.35.5 [SECURITY] #79
No reviewers
Labels
No labels
Compat/Breaking
Kind/Bug
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/Security
Kind/Testing
Priority
Critical
Priority
High
Priority
Low
Priority
Medium
Reviewed
Confirmed
Reviewed
Duplicate
Reviewed
Invalid
Reviewed
Won't Fix
Status
Abandoned
Status
Blocked
Status
Need More Info
No milestone
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
IC3P3/hcss-website!79
Loading…
Reference in a new issue
No description provided.
Delete branch "renovate/npm-sharp-vulnerability"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
0.35.4→0.35.5sharp : Vulnerability in librsvg dependency CVE-2026-96889
GHSA-wq5f-xc86-pv6w
More information
Details
Impact
A memory-related vulnerability has been discovered and fixed in the upstream librsvg dependency. When certain runtime-specific conditions apply, this vulnerability can lead to possible remote code execution (RCE) on glibc-based Linux.
Patches
Using prebuilt binaries provided by sharp?
Most people rely on the prebuilt binaries provided by sharp.
Please upgrade sharp to the latest version, currently 0.35.5, which provides librsvg 2.63.2.
Using a globally-installed librsvg?
Please ensure you are using the latest librsvg 2.63.2.
Workarounds
Add the following to your code to prevent sharp from decoding SVG images.
To avoid RCE, ensure you are using a
nodeexecutable binary compiled as a Position Independent Executable (PIE). Most Linux package managers already use this security-hardening feature however be warned that the "official" Node.js binaries do not.1
Severity
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:HReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Release Notes
lovell/sharp (sharp)
v0.35.5Compare Source
https://github.com/lovell/sharp-libvips/releases/tag/v1.3.4
Add upper bounds check on length of
linearand GIFdelayarrays.Improve error handing when WebAssembly fallback also fails.
#4593
@lazerg
TypeScript: Allow multi-frame options for JXL output.
#4602
@ramin-010
TypeScript: Remove non-existent named export.
#4604
Increase accepted dimensions when extending an image.
#4605
Improve gain map support for
extractandrotateoperations.#4606
Tests: Ensure composite tests pass on big endian platforms.
#4609
Configuration
📅 Schedule: (in timezone Europe/Berlin)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate.
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.Merge
Merge the changes and update on Forgejo.Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.