Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107379— enshrined/svg-sanitize: Denial of Service via DTD Attribute Declaration Crash

Quick assessment

Affected
darylldoyle svg-sanitizer
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

savg-sanitizer 是一个用于清理 SVG/XML 内容的 PHP 库。在 1.0.0 版本之前,svg-sanitizer 存在一个安全漏洞:攻击者可以构造一个包含 属性默认值的恶意 SVG DTD,从而在 中的 函数中对同一属性名触发两次 调用。第一次删除会移除显式定义的属性,而 DTD 中定义的默认值会在该属性被删除后重新生成;当 安全检查路径执行第二次删除操作时,会导致 libxml 内部状态损坏,进而使 PHP 工作进程终止。攻击者若能够向漏洞清理接口提交恶意 SVG 内容,即可反复中断 PHP

CVSS 6.5 · Medium

Affected Version Matrix 1

VendorProduct Version RangeStatus
darylldoyle svg-sanitizer < 1.0.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107379

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
enshrined/svg-sanitize: Denial of Service via DTD Attribute Declaration Crash
Source: CVE Program / CVE List V5
Vulnerability Description
savg-sanitizer is a PHP SVG/XML sanitizer. Prior to 1.0.0, svg-sanitizer allows a crafted SVG DTD with a #FIXED attribute default to make cleanAttributesOnWhitelist() perform a double DOMElement::removeAttribute() call on the same attribute name in src/Sanitizer.php. The first removal deletes the explicit attribute, while the DTD default rematerializes the value before the href safety path performs the second removal, which can corrupt libxml state and terminate the PHP worker. An attacker who can submit SVG content to a sanitization endpoint can repeatedly interrupt workers and degrade or exhaust application availability. This issue is fixed in version 1.0.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
不加限制或调节的资源分配
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
darylldoyle svg-sanitizer < 1.0.0 -

II. Public POCs for CVE-2026-107379

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107379

请登录查看更多情报信息。

Other References for CVE-2026-107379 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-107379

No comments yet


Leave a comment