{"id":"GHSA-4hgp-59h5-gvrj","summary":"ratex-parser panics on `\\verb` with a multibyte delimiter (UTF-8 byte-boundary slice)","details":"### Summary\n\nThe public parser entrypoint `ratex_parser::parse(&str)` panics on the **9-byte** input `\\verbéxé` (i.e. `\\verb` followed by the non-ASCII delimiter `é`). When handling a `\\verb` command, the parser slices the verbatim argument with **byte** indices (`arg[1..arg.len() - 1]`); if the delimiter character is multibyte UTF-8, index `1` lands inside that character and Rust panics with *“byte index 1 is not a char boundary”*. Because RaTeX’s release profile sets `panic = \"abort\"` (`Cargo.toml:48`), the panic aborts the **entire process** — not just the current request/thread — making this a hard denial of service for any service that renders untrusted LaTeX.\n\n\n\n### Details\n\n\n## Affected code\n\n`crates/ratex-parser/src/parser.rs`, `parse_symbol_inner`:\n\n```rust\nif let Some(stripped) = text.strip_prefix(\"\\\\verb\") {       // parser.rs:901\n    self.consume();\n    let arg = stripped.to_string();                         // e.g. \"éxé\"\n    let star = arg.starts_with('*');\n    let arg = if star { &arg[1..] } else { &arg };          // parser.rs:905  (also byte-sliced)\n    if arg.len() \u003c 2 {                                      // byte length\n        return Err(ParseError::new(\"\\\\verb assertion failed\", Some(&nucleus)));\n    }\n    let body = arg[1..arg.len() - 1].to_string();           // parser.rs:910  \u003c-- PANIC on multibyte delimiter\n    ...\n}\n```\n\nFor input `\\verbéxé`: `arg = \"éxé\"`, where `é` = `U+00E9` (bytes `C3 A9`). `arg.len()` is the **byte** length (5), the `\u003c 2` guard passes, and `arg[1..4]` starts at byte index 1 — inside the first `é` (bytes 0..2) — so the slice panics. The lexer groups `\\verb\u003cdelim\u003e…\u003cdelim\u003e` correctly with char semantics (`lexer.rs` `lex_verb`); only the parser mishandles it.\n\n### PoC\n\n\u003cimg width=\"1109\" height=\"205\" alt=\"image\" src=\"https://github.com/user-attachments/assets/cd4bc6ae-23dd-458f-826c-6ce4e85c7005\" /\u003e\n\n\n```\n$ printf '\\\\verb\\xc3\\xa9x\\xc3\\xa9\\n' | ./target/release/parse\nthread 'main' panicked at crates/ratex-parser/src/parser.rs:910:27:\nstart byte index 1 is not a char boundary; it is inside 'é' (bytes 0..2 of string)\nAborted (core dumped)            # exit 134 — panic=abort kills the whole process\n```\n\n### Impact\n\nAny application that renders untrusted LaTeX through RaTeX (web “render this math” endpoint, WASM in-browser use, the FFI embedded in another app) can be crashed by a tiny string. With `panic = \"abort\"` in release builds, the crash takes down the whole process / server, so a single malicious formula causes a full-service DoS (and, in batch pipelines, drops all queued work).\n\n## Remediation\n\nSlice by character boundaries instead of byte indices, mirroring the UTF-8-correct logic the lexer already uses. For example:\n\n```rust\nlet chars: Vec\u003cchar\u003e = arg.chars().collect();\nif chars.len() \u003c 2 { return Err(ParseError::new(\"\\\\verb assertion failed\", Some(&nucleus))); }\nlet body: String = chars[1..chars.len() - 1].iter().collect();\n```\n\n(Apply the same char-aware handling to the `*` strip at `parser.rs:905`.) More broadly, consider not using `panic = \"abort\"` for builds embedded in long-running services, and/or wrapping parsing in `catch_unwind` at the FFI/WASM boundary — but the byte-slice fix is the direct correction.","aliases":["CVE-2026-53530"],"modified":"2026-07-07T23:56:32.324787Z","published":"2026-07-07T23:39:12Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-07-07T23:39:12Z","nvd_published_at":null,"cwe_ids":["CWE-1285","CWE-248","CWE-400"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/erweixin/RaTeX/security/advisories/GHSA-4hgp-59h5-gvrj"},{"type":"PACKAGE","url":"https://github.com/erweixin/RaTeX"}],"affected":[{"package":{"name":"ratex-parser","ecosystem":"crates.io","purl":"pkg:cargo/ratex-parser"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.1.11"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-4hgp-59h5-gvrj/GHSA-4hgp-59h5-gvrj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}