Low · 3.8 PHP packages GHSA-v383-3rw5-q8rf CVE-2026-107379 PKSA-cbx2-m9db-bmzd
CVE-2026-107379 — enshrined/svg-sanitize: Denial of Service via DTD attribute
A flaw in enshrined/svg-sanitize can cause libxml state corruption and crash PHP workers when sanitizing specially crafted SVG DTDs; a vendor update 1.0.0 is available. [Sources: 3975,4172,8431,31853]
AI summary
CVE-2026-107379 is a denial-of-service issue in the PHP SVG sanitizer enshrined/svg-sanitize. The issue can terminate PHP workers processing malicious SVG input. A fix is available in the vendor update 1.0.0. [Sources: 3975,4172,8431,31853]
What happened
enshrined/svg-sanitize can be made to crash PHP workers when sanitizing a specially crafted SVG DTD. A DTD declaration using a #FIXED attribute default causes the sanitizer code path to call DOMElement::removeAttribute() twice on the same attribute name; the attribute is removed, then the DTD default rematerializes it before a second removal corrupts libxml state and can terminate the PHP worker. An attacker able to submit SVG content to a sanitization endpoint can repeatedly interrupt workers and degrade or exhaust availability. [Sources: 3975,4172,8431,31853]
Technical cause
The sanitizer's cleanAttributesOnWhitelist() path performs two removeAttribute() calls on the same attribute name when a crafted DTD provides a #FIXED attribute default. The first removal deletes the explicit attribute, the DTD default then rematerializes the attribute value, and the second removal corrupts libxml's state, causing the PHP worker to terminate. [Sources: 3975,4172,8431,31853]
Why it matters
Terminating PHP workers via malformed input can be used to degrade or deny service for applications that accept user-supplied SVGs and run the sanitizer synchronously. The vulnerability has a CVSS 3.1 base score of 6.5 (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H), indicating a network-accessible attack path that results in high impact to availability. [Sources: 3975,4172,8431,31853]
Who is affected
Projects and applications that include enshrined/svg-sanitize and expose an endpoint that accepts and sanitizes user-supplied SVG or XML input are affected. The advisory references affected ranges starting at 0 and fixed in 1.0.0; other sources also indicate builds up to and including 0.22.0 are affected. Check your dependency graph for enshrined/svg-sanitize. [Sources: 3975,4172,8431,31853]
Discovery and timeline
Public database entries for this issue were published on 2026-10-08. The package advisory and NVD entries list the vulnerability and remediation. The fact package does not include a discoverer name or a vendor statement beyond the fix; no evidence of exploitation is included. [Sources: 3975,4172,8431,31853]
Affected versions
According to the advisory data, the vulnerability affects enshrined/svg-sanitize from introduced version 0 up to the fixed release 1.0.0. Some registry entries describe affected builds as up to and including 0.22.0. Review your installed version against these ranges. [Sources: 3975,4172,8431,31853]
Fixes and mitigation
A vendor update is available: 1.0.0. Upgrading to that release resolves the double-removal behavior described in the advisory. If you cannot immediately update, consider blocking or sanitizing incoming SVG uploads at a higher level (for example, rejecting SVGs that include DTDs) to avoid processing untrusted DTD declarations. The fact package does not provide additional vendor mitigation guidance. [Sources: 3975,4172,8431,31853]
Recommended action
1) Inspect your dependency tree for enshrined/svg-sanitize and identify services that sanitize user-provided SVG/XML. 2) Upgrade to enshrined/svg-sanitize version 1.0.0. 3) As an interim mitigation, reject or pre-filter SVG inputs that contain DTD declarations before handing them to the sanitizer. 4) Monitor application worker stability and restart policies to reduce impact from unexpected worker termination. [Sources: 3975,4172,8431,31853]
PatchBriefing score
3.8 / 10 · Low
Official CVSS: 6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Why this score
The advisory lists a CVSS 3.1 base score of 6.5 (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). PatchWire's combined score is 3.8. Contributing factors in the fact package include: no evidence of known exploitation or public exploit (no contribution), EPSs data present but not raising score, the issue requires no user interaction (small positive contribution), and a fix is available. These values are taken directly from the supplied advisory data. [Sources: 3975,4172,8431,31853]
Affected versions
- enshrined/svg-sanitize ≥ 0 < 1.0.0
- vulnerable
- enshrined/svg-sanitize
- vulnerable
- enshrined/svg-sanitize <=0.22.0
- vulnerable
- enshrined/svg-sanitize <= 0.22.0
- vulnerable
- ≥ 1.0.0
- patched
Reported fixes
A vendor update is available: 1.0.0. Upgrading to that release resolves the double-removal behavior described in the advisory. If you cannot immediately update, consider blocking or sanitizing incoming SVG uploads at a higher level (for example, rejecting SVGs that include DTDs) to avoid processing untrusted DTD declarations. The fact package does not provide additional vendor mitigation guidance. [Sources: 3975,4172,8431,31853]
How this was built
4 source records were collected, matched and used to prepare the report above.
-
OSV.dev database
-
Packagist Security Advisories registry
-
GitHub Advisory Database database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email