Impact
The vulnerability originates in svg-sanitizer, a PHP SVG/XML sanitizer. A crafted SVG containing a DTD with a #FIXED attribute default triggers cleanAttributesOnWhitelist() to call DOMElement::removeAttribute() twice on the same attribute. The first call deletes the explicit attribute, but the DTD default recreates the value before the href safety path performs the second removal, corrupting libxml’s internal state and causing the PHP worker to terminate. This results in a denial of service as the application loses worker threads and can become unavailable if the attacks are repeated.
Affected Systems
The affected product is svg-sanitizer published by darylldoyle. Versions prior to 1.0.0 contain the flaw. Updating to release 1.0.0 or later removes the double-removal bug and restores normal worker stability.
Risk and Exploitability
The CVSS score is 6.5, indicating moderate impact. Because EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, no public exploits have been observed yet. The likely attack path is an attacker who can send crafted SVG payloads to an exposed sanitization endpoint. Although the exploit requires input injection, it can be automated and is straightforward once access to the endpoint is gained, potentially causing repeated worker crashes and application downtime.
OpenCVE Enrichment
Github GHSA