๐Ÿ” CVE Alert

CVE-2026-29112

HIGH 7.5

@dicebear/converter vulnerable to ncontrolled memory allocation via crafted SVG dimensions

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

DiceBear is an avatar library for designers and developers. Prior to version 9.4.0, the `ensureSize()` function in `@dicebear/converter` read the `width` and `height` attributes from the input SVG to determine the output canvas size for rasterization (PNG, JPEG, WebP, AVIF). An attacker who can supply a crafted SVG with extremely large dimensions (e.g. `width="999999999"`) could force the server to allocate excessive memory, leading to denial of service. This primarily affects server-side applications that pass untrusted or user-supplied SVGs to the converter's `toPng()`, `toJpeg()`, `toWebp()`, or `toAvif()` functions. Applications that only convert self-generated DiceBear avatars are not practically exploitable, but are still recommended to upgrade. This is fixed in version 9.4.0. The `ensureSize()` function no longer reads SVG attributes to determine output size. Instead, a new `size` option (default: 512, max: 2048) controls the output dimensions. Invalid values (NaN, negative, zero, Infinity) fall back to the default. If upgrading is not immediately possible, validate and sanitize the `width` and `height` attributes of any untrusted SVG input before passing it to the converter.

CWE CWE-770
Vendor dicebear
Product dicebear
Published Mar 18, 2026
Last Updated Mar 18, 2026
Stay Ahead of the Next One

Get instant alerts for dicebear dicebear

Be the first to know when new high vulnerabilities affecting dicebear dicebear are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

dicebear / dicebear
< 9.4.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/dicebear/dicebear/security/advisories/GHSA-v3r3-4qgc-vw66 github.com: https://github.com/dicebear/dicebear/commit/42a59eac46a3c68598859e608ec45e578b27614a github.com: https://github.com/dicebear/dicebear/releases/tag/v9.4.0