CVE-2026-53530

Summary

RaTeX is a KaTeX-compatible math rendering engine written in Rust. Prior to version 0.1.11, the public parser entrypoint ratex_parser::parse(&str) panics on the 9-byte input \verbéxé (i.e. \verb followed by the non-ASCII delimiter é). When handling a \verb command, the parser slices the verbatim argument with byte indices (arg[1..arg.len() - 1]); if the delimiter character is multibyte UTF-8, index 1 lands inside that character and Rust panics with “byte index 1 is not a char boundary”. Because RaTeX’s release profile sets panic = "abort" (Cargo.toml:48), the panic aborts the entire process — not just the current request/thread — making this a hard denial of service for any service that renders untrusted LaTeX. Version 0.1.11 fixes the issue.

Affected Software

VendorProductVersion RangeStatus
erweixinRaTeX< 0.1.11affected

Weaknesses

  • CWE-248: CWE-248: Uncaught Exception
  • CWE-400: CWE-400: Uncontrolled Resource Consumption
  • CWE-1285: CWE-1285: Improper Validation of Specified Index, Position, or Offset in Input

References