CVE WATCH / VULNERABILITY DETAIL

CVE-2026-107379

MEDIUMCVSS 6.5NVD feed

Published 8 October 2026 · tracked since 9 October 2026

Description

savg-sanitizer is a PHP SVG/XML sanitizer. Prior to 1.0.0, svg-sanitizer allows a crafted SVG DTD with a #FIXED attribute default to make cleanAttributesOnWhitelist() perform a double DOMElement::removeAttribute() call on the same attribute name in src/Sanitizer.php. The first removal deletes the ex

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-107379 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-107379

MEDIUMCVSS 6.5NVD feed

Published 8 October 2026 · tracked since 9 October 2026

Description

savg-sanitizer is a PHP SVG/XML sanitizer. Prior to 1.0.0, svg-sanitizer allows a crafted SVG DTD with a #FIXED attribute default to make cleanAttributesOnWhitelist() perform a double DOMElement::removeAttribute() call on the same attribute name in src/Sanitizer.php. The first removal deletes the ex

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]