Update dependency sharp to v0.35.5 [SECURITY] #79

Open
renovate-bot wants to merge 1 commit from renovate/npm-sharp-vulnerability into dev
Collaborator

This PR contains the following updates:

Package Change Age Confidence
sharp (source, changelog) 0.35.4 → 0.35.5 age confidence

sharp : Vulnerability in librsvg dependency CVE-2026-96889

GHSA-wq5f-xc86-pv6w

More information

Details

Impact

A memory-related vulnerability has been discovered and fixed in the upstream librsvg dependency. When certain runtime-specific conditions apply, this vulnerability can lead to possible remote code execution (RCE) on glibc-based Linux.

Patches
Using prebuilt binaries provided by sharp?

Most people rely on the prebuilt binaries provided by sharp.

Please upgrade sharp to the latest version, currently 0.35.5, which provides librsvg 2.63.2.

Using a globally-installed librsvg?

Please ensure you are using the latest librsvg 2.63.2.

Workarounds

Add the following to your code to prevent sharp from decoding SVG images.

sharp.block({ operation: ["VipsForeignLoadSvg"] });

To avoid RCE, ensure you are using a node executable binary compiled as a Position Independent Executable (PIE). Most Linux package managers already use this security-hardening feature however be warned that the "official" Node.js binaries do not.
1

Severity

  • CVSS Score: 8.9 / 10 (High)
  • Vector String: CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Release Notes

lovell/sharp (sharp)

v0.35.5

Compare Source

https://github.com/lovell/sharp-libvips/releases/tag/v1.3.4

  • Add upper bounds check on length of linear and GIF delay arrays.

  • Improve error handing when WebAssembly fallback also fails.
    #​4593
    @​lazerg

  • TypeScript: Allow multi-frame options for JXL output.
    #​4602
    @​ramin-010

  • TypeScript: Remove non-existent named export.
    #​4604

  • Increase accepted dimensions when extending an image.
    #​4605

  • Improve gain map support for extract and rotate operations.
    #​4606

  • Tests: Ensure composite tests pass on big endian platforms.
    #​4609


Configuration

📅 Schedule: (in timezone Europe/Berlin)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [sharp](https://sharp.pixelplumbing.com) ([source](https://github.com/lovell/sharp), [changelog](https://github.com/lovell/sharp/blob/main/docs/src/content/docs/changelog.md)) | [`0.35.4` → `0.35.5`](https://renovatebot.com/diffs/npm/sharp/0.35.4/0.35.5) | ![age](https://developer.mend.io/api/mc/badges/age/npm/sharp/0.35.5?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/sharp/0.35.4/0.35.5?slim=true) | --- ### sharp : Vulnerability in librsvg dependency CVE-2026-96889 [GHSA-wq5f-xc86-pv6w](https://github.com/advisories/GHSA-wq5f-xc86-pv6w) <details> <summary>More information</summary> #### Details ##### Impact A memory-related vulnerability has been discovered and fixed in the upstream librsvg dependency. When certain runtime-specific conditions apply, this vulnerability can lead to possible remote code execution (RCE) on glibc-based Linux. ##### Patches ##### Using prebuilt binaries provided by sharp? Most people rely on the prebuilt binaries provided by sharp. Please upgrade sharp to the latest version, currently 0.35.5, which provides librsvg 2.63.2. ##### Using a globally-installed librsvg? Please ensure you are using the latest librsvg 2.63.2. ##### Workarounds Add the following to your code to prevent sharp from decoding SVG images. ```js sharp.block({ operation: ["VipsForeignLoadSvg"] }); ``` To avoid RCE, ensure you are using a `node` executable binary compiled as a Position Independent Executable (PIE). Most Linux package managers already use this security-hardening feature however be warned that the "official" Node.js binaries do not. 1 #### Severity - CVSS Score: 8.9 / 10 (High) - Vector String: `CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H` #### References - [https://github.com/lovell/sharp/security/advisories/GHSA-wq5f-xc86-pv6w](https://github.com/lovell/sharp/security/advisories/GHSA-wq5f-xc86-pv6w) - [https://github.com/lovell/sharp/commit/96de105d9d36ab04c76c2b78b97255171630d236](https://github.com/lovell/sharp/commit/96de105d9d36ab04c76c2b78b97255171630d236) - [https://github.com/lovell/sharp](https://github.com/lovell/sharp) - [https://github.com/lovell/sharp/releases/tag/v0.35.5](https://github.com/lovell/sharp/releases/tag/v0.35.5) - [https://gitlab.gnome.org/GNOME/librsvg/-/work_items/1241](https://gitlab.gnome.org/GNOME/librsvg/-/work_items/1241) - [https://www.cve.org/CVERecord?id=CVE-2026-96889](https://www.cve.org/CVERecord?id=CVE-2026-96889) This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-wq5f-xc86-pv6w) and the [GitHub Advisory Database](https://github.com/github/advisory-database) ([CC-BY 4.0](https://github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Release Notes <details> <summary>lovell/sharp (sharp)</summary> ### [`v0.35.5`](https://github.com/lovell/sharp/releases/tag/v0.35.5) [Compare Source](https://github.com/lovell/sharp/compare/v0.35.4...v0.35.5) <https://github.com/lovell/sharp-libvips/releases/tag/v1.3.4> - Add upper bounds check on length of `linear` and GIF `delay` arrays. - Improve error handing when WebAssembly fallback also fails. [#&#8203;4593](https://github.com/lovell/sharp/pull/4593) [@&#8203;lazerg](https://github.com/lazerg) - TypeScript: Allow multi-frame options for JXL output. [#&#8203;4602](https://github.com/lovell/sharp/pull/4602) [@&#8203;ramin-010](https://github.com/ramin-010) - TypeScript: Remove non-existent named export. [#&#8203;4604](https://github.com/lovell/sharp/issues/4604) - Increase accepted dimensions when extending an image. [#&#8203;4605](https://github.com/lovell/sharp/issues/4605) - Improve gain map support for `extract` and `rotate` operations. [#&#8203;4606](https://github.com/lovell/sharp/issues/4606) - Tests: Ensure composite tests pass on big endian platforms. [#&#8203;4609](https://github.com/lovell/sharp/issues/4609) </details> --- ### Configuration 📅 **Schedule**: (in timezone Europe/Berlin) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMzQuMCIsInVwZGF0ZWRJblZlciI6IjQzLjIzNC4wIiwidGFyZ2V0QnJhbmNoIjoiZGV2IiwibGFiZWxzIjpbXX0=-->
Update dependency sharp to v0.35.5 [SECURITY]
Some checks failed
CI / test (pull_request) Failing after 4s
CI / build (pull_request) Has been skipped
CI / deploy-dev (pull_request) Has been skipped
CI / deploy-prod (pull_request) Has been skipped
a51a0cac2c
renovate-bot scheduled this pull request to auto merge when all checks succeed 2026-10-07 21:01:28 +02:00
Some checks failed
CI / test (pull_request) Failing after 4s
CI / build (pull_request) Has been skipped
CI / deploy-dev (pull_request) Has been skipped
CI / deploy-prod (pull_request) Has been skipped
This pull request can be merged automatically.
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin renovate/npm-sharp-vulnerability:renovate/npm-sharp-vulnerability
git switch renovate/npm-sharp-vulnerability

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch dev
git merge --no-ff renovate/npm-sharp-vulnerability
git switch renovate/npm-sharp-vulnerability
git rebase dev
git switch dev
git merge --ff-only renovate/npm-sharp-vulnerability
git switch renovate/npm-sharp-vulnerability
git rebase dev
git switch dev
git merge --no-ff renovate/npm-sharp-vulnerability
git switch dev
git merge --squash renovate/npm-sharp-vulnerability
git switch dev
git merge --ff-only renovate/npm-sharp-vulnerability
git switch dev
git merge renovate/npm-sharp-vulnerability
git push origin dev
Sign in to join this conversation.
No reviewers
No milestone
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
IC3P3/hcss-website!79
No description provided.