CVE Watchtower

← Back to CVE List

CVE-2026-90596NVD

Description

A weakness has been identified in embedded-graphics up to 0.8.2 on 32-bit. Impacted is the function ImageRaw::new/bytes_per_row of the file src/image/image_raw.rs. This manipulation causes integer overflow. The attack is possible to be carried out remotely. Upgrading the affected component is recommended. The project was informed of the problem early through an issue report but has not responded yet.
Severity Level
MEDIUM (6.5)
Published Date
13/09/2026
Last Modified
15/09/2026
Exploitation Status
????
EPSS Score
0.34% (percentile 27.1%)

CVSS Base Metrics

CVSS v3 (3.1)
MEDIUM 6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:X/RL:O/RC:C
CVSS v4 (4.0)
MEDIUM 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X

Weaknesses (CWE)

CWE-190 - Integer OverflowCWE-189 - Numeric Error

Affected & Patched Versions

ProductAffected VersionsPatched Version
n/a embedded-graphics0.8.0, 0.8.1, 0.8.2N/A
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.