CVE-2023-46045: Graphviz

High severity, CVSS 7.8. EPSS: 0.8% chance of exploitation in the next 30 days.

Graphviz 2.36.0 through 9.x before 10.0.1 has an out-of-bounds read via a crafted config6a file. NOTE: exploitability may be uncommon because this file is typically owned by root.

Affected products

  • Graphviz Graphviz: from 2.36.0, before 10.0.0 (fixed in 10.0.0)

Published 2024-02-02. Last modified 2026-06-17.