PatchSiren cyber security CVE debrief
CVE-2026-107379 darylldoyle CVE debrief
A crafted SVG file crashes the PHP process when sanitized by `enshrined/svg-sanitize` (versions through 0.22.x) due to a type confusion bug in the sanitizer's `cleanAttributesOnWhitelist()` method. This issue affects multiple projects, including WordPress Safe SVG plugin, TYPO3, and Drupal. The vulnerability is triggered when the sanitizer attempts to remove attributes from an SVG file, causing a denial-of-service attack. Defenders should prioritize verification and remediation efforts, especially for systems using `enshrined/svg-sanitize`, WordPress Safe SVG plugin, TYPO3, and Drupal.
- Vendor
- darylldoyle
- Product
- enshrined/svg-sanitize
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for systems using `enshrined/svg-sanitize`, WordPress Safe SVG plugin, TYPO3, and Drupal should assess the impact of this vulnerability and prioritize verification and remediation efforts.
Why it matters
CVE-2026-107379 is a denial-of-service vulnerability in `enshrined/svg-sanitize` that can crash the PHP process when sanitizing crafted SVG files. Defenders should prioritize verification and remediation efforts, especially for systems using `enshrined/svg-sanitize`, WordPress Safe SVG plugin, TYPO3, and Drupal.
- Potential denial-of-service attacks against systems using `enshrined/svg-sanitize`, WordPress Safe SVG plugin, TYPO3, and Drupal.
- Verification of exposure and impact is required to prevent potential attacks.
- Remediation priority is high for systems using vulnerable versions of `enshrined/svg-sanitize`.
- Further investigation is needed to determine the full scope of affected systems and potential consequences.
Technical summary
The `enshrined/svg-sanitize` library is vulnerable to a denial-of-service attack when sanitizing crafted SVG files. The vulnerability is caused by a type confusion bug in the sanitizer's `cleanAttributesOnWhitelist()` method, which calls `DOMElement::removeAttribute()` twice on the same attribute name, triggering a PHP ext/dom type confusion that kills the PHP-FPM worker. This issue affects multiple projects, including WordPress Safe SVG plugin, TYPO3, and Drupal. Defenders should prioritize verifying exposure and assessing the impact of this vulnerability on their systems.
Defensive priority
Defenders should prioritize verifying exposure and assessing the impact of this vulnerability on their systems, especially those using `enshrined/svg-sanitize`, WordPress Safe SVG plugin, TYPO3, and Drupal. Immediate action is required to prevent potential denial-of-service attacks.
Recommended defensive actions
- Verify if your system uses `enshrined/svg-sanitize`, WordPress Safe SVG plugin, TYPO3, or Drupal and assess the impact of this vulnerability.
- Update `enshrined/svg-sanitize` to version 1.0.0 or later.
- Implement input validation and sanitization for SVG files.
- Monitor system logs for potential denial-of-service attacks.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The source corpus provides detailed information about the vulnerability, including a crafted SVG file that crashes the PHP process when sanitized by `enshrined/svg-sanitize`. The sanitizer's `cleanAttributesOnWhitelist()` method calls `DOMElement::removeAttribute()` twice on the same attribute name, triggering a PHP ext/dom type confusion that kills the PHP-FPM worker.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107379 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107379
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107379 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107379
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
enshrined/svg-sanitize: Denial of Service via DTD Attribute Declaration Crash
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/Packagist/GHSA-v383-3rw5-q8rf.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/darylldoyle/svg-sanitizer/security/advisories/GHSA-v383-3rw5-q8rf
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/darylldoyle/svg-sanitizer/commit/23877db7e76f1e1df5c3e65ab30239219c3d2867
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/darylldoyle/svg-sanitizer
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/darylldoyle/svg-sanitizer/releases/tag/1.0.0
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.