CVE-2024-36761: Gfx-RS Naga

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

naga v0.14.0 was discovered to contain a stack overflow via the component /wgsl/parse/mod.rs.

Affected products

  • Gfx-RS Naga: before 25.0.0 (fixed in 25.0.0)
  • Gfx-RS Wgpu: before 25.0.0 (fixed in 25.0.0)

Published 2024-06-12. Last modified 2026-06-17.