---
id: CVE-2026-90596
title: A weakness has been identified in embedded-graphics up to 0.8.2 on 32-bit
summary: >-
  A weakness has been identified in embedded-graphics up to 0.8.2 on 32-bit.
  Impacted is the function ImageRaw::new/bytes_per_row of the file
  src/image/image_raw.rs. This manipulation causes integer overflow. The attack
  is possible to be c…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'
cwe:
  - CWE-189
  - CWE-190
product: embedded-graphics
affected:
  - embedded-graphics 0.8.0
  - embedded-graphics 0.8.1
  - embedded-graphics 0.8.2
published: '2026-09-13'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T18:19:37.327'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90596'
references:
  - url: 'https://github.com/embedded-graphics/embedded-graphics/'
    label: cna@vuldb.com
  - url: 'https://github.com/embedded-graphics/embedded-graphics/issues/820'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-90596'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/913790'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403178'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403178/cti'
    label: cna@vuldb.com
  - url: 'https://github.com/embedded-graphics/embedded-graphics/issues/820'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-15T17:49:06.274626Z'
epss: 0.00577
epssPercentile: 0.45158
ingestedAt: '2026-09-14T15:23:07.468Z'
---

## Overview

A weakness has been identified in embedded-graphics up to 0.8.2 on 32-bit. Impacted is the function ImageRaw::new/bytes_per_row of the file src/image/image_raw.rs. This manipulation causes integer overflow. The attack is possible to be carried out remotely. Upgrading the affected component is recommended. The project was informed of the problem early through an issue report but has not responded yet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
