CVE Watchtower

← Back to CVE List

CVE-2026-90593NVD

Description

A vulnerability was determined in embedded-graphics up to 0.8.2. This affects the function ImageRaw::draw_sub_image of the file src/image/image_raw.rs. Executing a manipulation of the argument width can lead to integer overflow. The attack may be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.
Severity Level
HIGH (7.3)
Published Date
13/09/2026
Last Modified
16/09/2026
Exploitation Status
????
EPSS Score
0.38% (percentile 32.0%)

CVSS Base Metrics

CVSS v3 (3.1)
HIGH 7.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R
CVSS v4 (4.0)
MEDIUM 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X

Weaknesses (CWE)

CWE-190 - Integer OverflowCWE-189 - Numeric Error

Affected & Patched Versions

ProductAffected VersionsPatched Version
n/a embedded-graphics0.8.0, 0.8.1, 0.8.2N/A
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.