Skip to content

chore(deps): update dependency sharp to v0.35.5 [security] - #87

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-sharp-vulnerability
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-sharp-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
sharp (source, changelog) 0.35.4 → 0.35.5 age confidence

sharp : Vulnerability in librsvg dependency CVE-2026-96889

GHSA-wq5f-xc86-pv6w

More information

Details

Impact

A memory-related vulnerability has been discovered and fixed in the upstream librsvg dependency. When certain runtime-specific conditions apply, this vulnerability can lead to possible remote code execution (RCE) on glibc-based Linux.

Patches
Using prebuilt binaries provided by sharp?

Most people rely on the prebuilt binaries provided by sharp.

Please upgrade sharp to the latest version, currently 0.35.5, which provides librsvg 2.63.2.

Using a globally-installed librsvg?

Please ensure you are using the latest librsvg 2.63.2.

Workarounds

Add the following to your code to prevent sharp from decoding SVG images.

sharp.block({ operation: ["VipsForeignLoadSvg"] });

To avoid RCE, ensure you are using a node executable binary compiled as a Position Independent Executable (PIE). Most Linux package managers already use this security-hardening feature however be warned that the "official" Node.js binaries do not.
1

Severity

  • CVSS Score: 8.9 / 10 (High)
  • Vector String: CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

lovell/sharp (sharp)

v0.35.5

Compare Source

https://github.com/lovell/sharp-libvips/releases/tag/v1.3.4

  • Add upper bounds check on length of linear and GIF delay arrays.

  • Improve error handing when WebAssembly fallback also fails.
    #​4593
    @​lazerg

  • TypeScript: Allow multi-frame options for JXL output.
    #​4602
    @​ramin-010

  • TypeScript: Remove non-existent named export.
    #​4604

  • Increase accepted dimensions when extending an image.
    #​4605

  • Improve gain map support for extract and rotate operations.
    #​4606

  • Tests: Ensure composite tests pass on big endian platforms.
    #​4609


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@vercel

vercel Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
semantic-release-docs Ready Ready Preview Oct 8, 2026 1:14pm UTC

Request Review

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedsharp@​0.35.4 ⏵ 0.35.597 +1100 +16100 +194100

View full report

This branch was successfully deployed

1 active deployment
Preview — 292ad47a Deployed Oct 8, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants