Description
The svg_optimizer gem before 0.3.0 for Ruby performs entity expansion on untrusted documents.
Published: 2026-09-14
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

The svg_optimizer Ruby gem, in releases older than 0.3.0, expands external entities when parsing SVG input that it cannot trust. This expansion can cause the parser to consume excessive resources or become unresponsive, leading to a denial‑of‑service condition for any process that processes the vulnerable SVG file. The flaw is an improper handling of external entity references, identified as CWE‑776.

Affected Systems

Affected systems are installations of the fnando:svg_optimizer gem for Ruby that are any version prior to 0.3.0. This includes users who build or deploy Ruby applications that rely on this gem to process incoming SVG files, especially in web services accepting user‑uploaded graphics.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity, and the EPSS score of 0.00363 shows a very low probability of exploitation. The gem is not listed in CISA’s KEV catalog, suggesting no known widespread exploitation. The likely attack vector involves submitting a malicious SVG file to an application that processes it with svg_optimizer; while the exact execution path is not detailed, it could be via an HTTP endpoint or a file import routine. Administrators should consider the risk of local denial of service if the gem is used in trusted or high‑availability contexts.

Generated by OpenCVE AI on September 15, 2026 at 16:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the svg_optimizer gem to version 0.3.0 or later.
  • If upgrading is not immediately possible, configure the gem to disable or limit entity expansion, or validate inputs before passing to the sanitizer.
  • Validate incoming SVG documents for size and entity usage prior to processing, or use a secondary library that safely handles external entities.

Generated by OpenCVE AI on September 15, 2026 at 16:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-6hvg-62q8-95v7 svg_optimizer rubygem external XML entity (XXE) vulnerability
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Fnando
Fnando svg Optimizer
Vendors & Products Fnando
Fnando svg Optimizer

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Title svg_optimizer Ruby Gem Allows Entity Expansion Leading to Denial of Service

Mon, 14 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via Entity Expansion in svg_optimizer gem

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title Denial of Service via Entity Expansion in svg_optimizer gem

Mon, 14 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-776
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Mon, 14 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Description The svg_optimizer gem before 0.3.0 for Ruby performs entity expansion on untrusted documents.
References

Subscriptions

Fnando Svg Optimizer
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T16:25:20.700Z

Reserved: 2023-10-16T00:00:00.000Z

Link: CVE-2023-46035

cve-icon Vulnrichment

Updated: 2026-09-14T16:25:17.614Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T06:16:54.500

Modified: 2026-09-22T20:00:03.713

Link: CVE-2023-46035

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:47:04Z

Weaknesses
  • CWE-776

    Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')