Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 4.2 PHP packages GHSA-m9xh-6747-9r6f CVE-2026-107381 PKSA-6j95-1jtb-x6wc

svg-sanitizer: Mixed-case xlink:HrEf skips the <use> nesting-DoS check (CVE-2026-107381)

A case-sensitive node selection in Resolver::processReferences lets mixed-case xlink:HrEf bypass the <use> nesting-DoS check. The sanitizer later canonicalizes the attribute name, returning a live nesting structure. A fix is available in 1.0.0. [CVE-2026-107381, GHSA-m9xh-6747-9r6f]

Synthesized by AI from 3 sources · updated 1 hour ago

AI summary

This advisory covers CVE-2026-107381 in enshrined/svg-sanitize: the resolver that builds the <use> reference graph matches attribute node names case-sensitively, allowing mixed-case names such as xlink:HrEf to be omitted from the graph and therefore to escape the sanitizer's nesting-DoS nullification. The sanitizer later lowercases attribute names and returns a file that still contains the original nesting structure. (Sources: OSV.dev, Packagist, GitHub Advisory Database.)

What happened

Resolver::processReferences() selects <use> elements with a case-sensitive XPath predicate (e.g. use[@href or @xlink:href]); a mixed-case attribute name such as xlink:HrEf is not matched and so is not added to the reference graph. Later in the same sanitize pass, Sanitizer::cleanHrefAttributes() canonicalizes attribute names (lowercasing them) and so the output contains canonical xlink:href attributes while the resolver never nullified the nested <use> structure. The result is a nesting DoS that the sanitizer would have removed if canonical casing had been present in the input. (Sources: 3974, 4173, 8432)

Technical cause

The bug is an ordering and case-sensitivity issue: the resolver builds a reference graph using a case-sensitive node selection, then later code normalizes attribute names to lowercase. Because the resolver never sees the canonical name, nodes with mixed-case attribute names are excluded from the graph and are not nullified by the nesting-DoS protection. The advisory describes two remediation approaches: make name matching case-insensitive when building the graph or run attribute canonicalization before the resolver collects references. (Sources: 3974, 4173, 8432)

Why it matters

An attacker who can supply an SVG (for example via upload or paste) to an application that uses this library can submit a file that preserves a deeply nested <use> structure despite the sanitizer. The sanitized output will contain canonical xlink:href attributes while retaining the original nesting, which is exactly the structure the library's useNestingLimit exists to neutralize. The practical downstream cost (renderer CPU or memory) was not measured in the advisory; the advisory's proof-of-concept measured that nullification was skipped and attributes were re-canonicalized. (Sources: 3974, 4173, 8432)

Who is affected

Projects and applications that use enshrined/svg-sanitize to sanitize user-supplied SVGs and that are running affected releases are at risk. Exploitation requires only the ability to submit or paste an SVG; no special privileges are required. (Sources: 3974, 4173, 8432)

Discovery and timeline

The advisory was published on 2026-10-08T19:41:10+02:00. The report includes a proof-of-concept run against tag 0.22.0 and test observations on PHP 8.5.9 showing that a canonical input is reduced from 201 <use> elements to 0, while the mixed-case input remains at 201 and the output attribute name is canonicalized. The advisory does not include claims of active exploitation or a vendor statement in the provided sources. (Sources: 3974, 4173, 8432)

Affected versions

The advisory indicates that releases up to and including 0.22.0 are affected. A fixed release is available in 1.0.0. If you cannot update, treat any deployment using <= 0.22.0 as vulnerable. (Sources: 3974, 4173, 8432)

Fixes and mitigation

A fix is available; the advisory lists 1.0.0 as the fixed version. The advisory's suggested technical remediations are: make the resolver's selection handle attribute/local-name matching case-insensitively and resolve hrefs in PHP, or move attribute canonicalization so it runs before the resolver builds the reference graph. Both approaches prevent the resolver from missing nodes due to mixed-case attribute names. (Sources: 3974, 4173, 8432)

Recommended action

Update enshrined/svg-sanitize to 1.0.0 as soon as practical. If you cannot apply the update immediately, apply a local mitigation that ensures attribute names are canonicalized before the reference graph is built or backport the resolver fix that accepts mixed-case attribute names when locating <use> nodes. Verify sanitization results with the library's test fixtures (the advisory references useDosTest.svg) to ensure the nesting structure is being removed. (Sources: 3974, 4173, 8432)

PatchBriefing score

4.2 / 10 · Medium

Official CVSS: 6.5

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Why this score

CVSS v3.1 base score is 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). This reflects: network attack vector (AV:N), low attack complexity (AC:L), no privileges required (PR:N), user interaction required (UI:R), unchanged scope (S:U), no confidentiality or integrity impact (C:N/I:N) and HIGH impact on availability (A:H). The advisory's PatchWire score is 4.2; that score accounts for the CVSS base plus factors such as unauthenticated remote attackability and lack of known public exploits. (Sources: 3974, 4173, 8432)

Affected versions

enshrined/svg-sanitize ≥ 0 < 1.0.0
vulnerable
enshrined/svg-sanitize
vulnerable
enshrined/svg-sanitize <=0.22.0
vulnerable
enshrined/svg-sanitize <= 0.22.0
vulnerable
≥ 1.0.0
patched

Reported fixes

A fix is available; the advisory lists 1.0.0 as the fixed version. The advisory's suggested technical remediations are: make the resolver's selection handle attribute/local-name matching case-insensitively and resolve hrefs in PHP, or move attribute canonicalization so it runs before the resolver builds the reference graph. Both approaches prevent the resolver from missing nodes due to mixed-case attribute names. (Sources: 3974, 4173, 8432)

How this was built

3 source records were collected, matched and used to prepare the report above.

  • OSV.dev database
  • Packagist Security Advisories registry
  • GitHub Advisory Database database
Unified report
svg-sanitizer: Mixed-case xlink:HrEf skips the <use> nesting-DoS check (CVE-2026-107381)
1 article · 3 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email