PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107379 darylldoyle CVE debrief

A crafted SVG file crashes the PHP process when sanitized by `enshrined/svg-sanitize` (versions through 0.22.x) due to a type confusion bug in the sanitizer's `cleanAttributesOnWhitelist()` method. This issue affects multiple projects, including WordPress Safe SVG plugin, TYPO3, and Drupal. The vulnerability is triggered when the sanitizer attempts to remove attributes from an SVG file, causing a denial-of-service attack. Defenders should prioritize verification and remediation efforts, especially for systems using `enshrined/svg-sanitize`, WordPress Safe SVG plugin, TYPO3, and Drupal.

Vendor
darylldoyle
Product
enshrined/svg-sanitize
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for systems using `enshrined/svg-sanitize`, WordPress Safe SVG plugin, TYPO3, and Drupal should assess the impact of this vulnerability and prioritize verification and remediation efforts.

Why it matters

CVE-2026-107379 is a denial-of-service vulnerability in `enshrined/svg-sanitize` that can crash the PHP process when sanitizing crafted SVG files. Defenders should prioritize verification and remediation efforts, especially for systems using `enshrined/svg-sanitize`, WordPress Safe SVG plugin, TYPO3, and Drupal.

  • Potential denial-of-service attacks against systems using `enshrined/svg-sanitize`, WordPress Safe SVG plugin, TYPO3, and Drupal.
  • Verification of exposure and impact is required to prevent potential attacks.
  • Remediation priority is high for systems using vulnerable versions of `enshrined/svg-sanitize`.
  • Further investigation is needed to determine the full scope of affected systems and potential consequences.

Technical summary

The `enshrined/svg-sanitize` library is vulnerable to a denial-of-service attack when sanitizing crafted SVG files. The vulnerability is caused by a type confusion bug in the sanitizer's `cleanAttributesOnWhitelist()` method, which calls `DOMElement::removeAttribute()` twice on the same attribute name, triggering a PHP ext/dom type confusion that kills the PHP-FPM worker. This issue affects multiple projects, including WordPress Safe SVG plugin, TYPO3, and Drupal. Defenders should prioritize verifying exposure and assessing the impact of this vulnerability on their systems.

Defensive priority

Defenders should prioritize verifying exposure and assessing the impact of this vulnerability on their systems, especially those using `enshrined/svg-sanitize`, WordPress Safe SVG plugin, TYPO3, and Drupal. Immediate action is required to prevent potential denial-of-service attacks.

Recommended defensive actions

  • Verify if your system uses `enshrined/svg-sanitize`, WordPress Safe SVG plugin, TYPO3, or Drupal and assess the impact of this vulnerability.
  • Update `enshrined/svg-sanitize` to version 1.0.0 or later.
  • Implement input validation and sanitization for SVG files.
  • Monitor system logs for potential denial-of-service attacks.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The source corpus provides detailed information about the vulnerability, including a crafted SVG file that crashes the PHP process when sanitized by `enshrined/svg-sanitize`. The sanitizer's `cleanAttributesOnWhitelist()` method calls `DOMElement::removeAttribute()` twice on the same attribute name, triggering a PHP ext/dom type confusion that kills the PHP-FPM worker.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107379 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107379

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107379 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107379

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • enshrined/svg-sanitize: Denial of Service via DTD Attribute Declaration Crash

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/Packagist/GHSA-v383-3rw5-q8rf.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/darylldoyle/svg-sanitizer/security/advisories/GHSA-v383-3rw5-q8rf

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/darylldoyle/svg-sanitizer/commit/23877db7e76f1e1df5c3e65ab30239219c3d2867

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/darylldoyle/svg-sanitizer

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/darylldoyle/svg-sanitizer/releases/tag/1.0.0

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.