🔐 CVE Alert

CVE-2026-53530

UNKNOWN 0.0

ratex-parser panics on `\verb` with a multibyte delimiter (UTF-8 byte-boundary slice)

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

RaTeX is a KaTeX-compatible math rendering engine written in Rust. Prior to version 0.1.11, the public parser entrypoint `ratex_parser::parse(&str)` panics on the 9-byte input `\verbéxé` (i.e. `\verb` followed by the non-ASCII delimiter `é`). When handling a `\verb` command, the parser slices the verbatim argument with byte indices (`arg[1..arg.len() - 1]`); if the delimiter character is multibyte UTF-8, index `1` lands inside that character and Rust panics with *“byte index 1 is not a char boundary”*. Because RaTeX’s release profile sets `panic = "abort"` (`Cargo.toml:48`), the panic aborts the entire process — not just the current request/thread — making this a hard denial of service for any service that renders untrusted LaTeX. Version 0.1.11 fixes the issue.

CWE CWE-248 CWE-400 CWE-1285
Vendor erweixin
Product ratex
Published Aug 21, 2026
Stay Ahead of the Next One

Get instant alerts for erweixin ratex

Be the first to know when new unknown vulnerabilities affecting erweixin ratex are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

erweixin / RaTeX
< 0.1.11

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/erweixin/RaTeX/security/advisories/GHSA-4hgp-59h5-gvrj