Impact
The svg_optimizer Ruby gem, in releases older than 0.3.0, expands external entities when parsing SVG input that it cannot trust. This expansion can cause the parser to consume excessive resources or become unresponsive, leading to a denial‑of‑service condition for any process that processes the vulnerable SVG file. The flaw is an improper handling of external entity references, identified as CWE‑776.
Affected Systems
Affected systems are installations of the fnando:svg_optimizer gem for Ruby that are any version prior to 0.3.0. This includes users who build or deploy Ruby applications that rely on this gem to process incoming SVG files, especially in web services accepting user‑uploaded graphics.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, and the EPSS score of 0.00363 shows a very low probability of exploitation. The gem is not listed in CISA’s KEV catalog, suggesting no known widespread exploitation. The likely attack vector involves submitting a malicious SVG file to an application that processes it with svg_optimizer; while the exact execution path is not detailed, it could be via an HTTP endpoint or a file import routine. Administrators should consider the risk of local denial of service if the gem is used in trusted or high‑availability contexts.
OpenCVE Enrichment
Github GHSA