highVulnerability

CVE-2026-53530

### Summary The public parser entrypoint `ratex_parser::parse(&str)` panics on the **9-byte** input `\verbéxé` (i.e. `\verb` followed by the non-ASCII delimiter `é`). When handling a `\verb` command, the parser slices the verbatim argument with **byte** indices (`arg[1..arg.len() - 1]`); if the delimiter character is multibyte UTF-8, index `1` lands inside that character and Rust panics with *“byte index 1 is not a char boundary”*. Because RaTeX’s release profile sets `panic = "abort"` (`Cargo.toml:48`), the panic aborts the **entire process** — not just the current request/thread — making this a hard denial of service for any service that renders untrusted LaTeX. ### Details ## Affected code `crates/ratex-parser/src/parser.rs`, `parse_symbol_inner`: ```rust if let Some(stripped) = text.strip_prefix("\\verb") { // parser.rs:901 self.consume(); let arg = stripped.to_string(); // e.g. "éxé" let star = arg.starts_with('*'); let arg = if star { &arg[1..] } else { &arg }; // parser.rs:905 (also byte-sliced) if arg.len() < 2 { // byte length return Err(ParseError::new("\\verb assertion failed", Some(&nucleus))); } let body = arg[1..arg.len() - 1].to_string(); // parser.rs:910 <-- PANIC on multibyte delimiter ... } ``` For input `\verbéxé`: `arg = "éxé"`, where `é` = `U+00E9` (bytes `C3 A9`). `arg.len()` is the **byte** length (5), the `< 2` guard passes, and `arg[1..4]` starts at byte index 1 — inside the first `é` (bytes 0..2) — so the slice panics. The lexer groups `\verb<delim>…<delim>` correctly with char semantics (`lexer.rs` `lex_verb`); only the parser mishandles it. ### PoC <img width="1109" height="205" alt="image" src="https://github.com/user-attachments/assets/cd4bc6ae-23dd-458f-826c-6ce4e85c7005" /> ``` $ printf '\\verb\xc3\xa9x\xc3\xa9\n' | ./target/release/parse thread 'main' panicked at crates/ratex-parser/src/parser.r

Properties

ghsa_id
GHSA-4hgp-59h5-gvrj
severity
high
summary
ratex-parser panics on `\verb` with a multibyte delimiter (UTF-8 byte-boundary slice)
cve_id
CVE-2026-53530
is_ghsa_only
false
ghsa_published
2026-07-07T23:39:12Z
source_url
https://github.com/advisories/GHSA-4hgp-59h5-gvrj
ghsa_updated
2026-07-07T23:39:13Z

Related Entities (6)

VULNERABLE_TO (1)

[Software]rust/ratex-parser

AFFECTS (1)

[Software]rust/ratex-parser

HAS_WEAKNESS (3)

[Weakness]Uncaught Exception
[Weakness]Improper Validation of Specified Index, Position, or Offset in Input
[Weakness]Uncontrolled Resource Consumption

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-53530 — Ninja Signal Threat Intelligence | Ninja Signal