


Perceptive Security
SOC/SIEM Consultancy

DiceBear is an avatar library for designers and developers. Prior to version 9.4.0, the `ensureSize()` function in `@dicebear/converter` read the `width` and `h…
Published:
17 March 2026 at 23:00:00
Alert date:
18 March 2026 at 20:02:47
Source:
nvd.nist.gov
Supply Chain & Dependencies, Web Technologies
DiceBear avatar library versions prior to 9.4.0 contain a vulnerability in the ensureSize() function of @dicebear/converter that allows attackers to cause denial of service through memory exhaustion. The vulnerability occurs when processing untrusted SVG files with extremely large dimensions, forcing excessive memory allocation during rasterization. Server-side applications using converter functions toPng(), toJpeg(), toWebp(), or toAvif() with user-supplied SVGs are at risk. The issue is fixed in version 9.4.0 by implementing size limits and validation controls.
Technical details
Mitigation steps:
Affected products:
DiceBear
@dicebear/converter
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-29112
https://github.com/dicebear/dicebear/commit/42a59eac46a3c68598859e608ec45e578b27614a
https://github.com/dicebear/dicebear/releases/tag/v9.4.0
https://github.com/dicebear/dicebear/security/advisories/GHSA-v3r3-4qgc-vw66
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
