Description
savg-sanitizer is a PHP SVG/XML sanitizer. Prior to 1.0.0, svg-sanitizer allows a crafted SVG DTD with a #FIXED attribute default to make cleanAttributesOnWhitelist() perform a double DOMElement::removeAttribute() call on the same attribute name in src/Sanitizer.php. The first removal deletes the explicit attribute, while the DTD default rematerializes the value before the href safety path performs the second removal, which can corrupt libxml state and terminate the PHP worker. An attacker who can submit SVG content to a sanitization endpoint can repeatedly interrupt workers and degrade or exhaust application availability. This issue is fixed in version 1.0.0.
Published: 2026-10-08
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service (worker termination and application availability interruption)
Action: Apply Patch
AI Analysis

Impact

The vulnerability originates in svg-sanitizer, a PHP SVG/XML sanitizer. A crafted SVG containing a DTD with a #FIXED attribute default triggers cleanAttributesOnWhitelist() to call DOMElement::removeAttribute() twice on the same attribute. The first call deletes the explicit attribute, but the DTD default recreates the value before the href safety path performs the second removal, corrupting libxml’s internal state and causing the PHP worker to terminate. This results in a denial of service as the application loses worker threads and can become unavailable if the attacks are repeated.

Affected Systems

The affected product is svg-sanitizer published by darylldoyle. Versions prior to 1.0.0 contain the flaw. Updating to release 1.0.0 or later removes the double-removal bug and restores normal worker stability.

Risk and Exploitability

The CVSS score is 6.5, indicating moderate impact. Because EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, no public exploits have been observed yet. The likely attack path is an attacker who can send crafted SVG payloads to an exposed sanitization endpoint. Although the exploit requires input injection, it can be automated and is straightforward once access to the endpoint is gained, potentially causing repeated worker crashes and application downtime.

Generated by OpenCVE AI on October 8, 2026 at 19:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade svg-sanitizer to version 1.0.0 or later.
  • Restrict access to the sanitization endpoint and implement rate limiting or quarantine of untrusted input sources.
  • Add monitoring to automatically restart PHP workers that terminate unexpectedly and alert administrators when crashes occur.

Generated by OpenCVE AI on October 8, 2026 at 19:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-v383-3rw5-q8rf enshrined/svg-sanitize: Denial of Service via DTD Attribute Declaration Crash
History

Thu, 08 Oct 2026 18:15:00 +0000

Type Values Removed Values Added
Description savg-sanitizer is a PHP SVG/XML sanitizer. Prior to 1.0.0, svg-sanitizer allows a crafted SVG DTD with a #FIXED attribute default to make cleanAttributesOnWhitelist() perform a double DOMElement::removeAttribute() call on the same attribute name in src/Sanitizer.php. The first removal deletes the explicit attribute, while the DTD default rematerializes the value before the href safety path performs the second removal, which can corrupt libxml state and terminate the PHP worker. An attacker who can submit SVG content to a sanitization endpoint can repeatedly interrupt workers and degrade or exhaust application availability. This issue is fixed in version 1.0.0.
Title enshrined/svg-sanitize: Denial of Service via DTD Attribute Declaration Crash
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-08T18:04:42.293Z

Reserved: 2026-10-07T21:07:54.987Z

Link: CVE-2026-107379

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-08T18:17:23.603

Modified: 2026-10-08T21:35:53.890

Link: CVE-2026-107379

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T19:45:07Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling