CVE-2023-50251

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-50251
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-50251.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-50251
Aliases
Downstream
Related
Published
2023-12-12T21:15:08Z
Modified
2025-09-24T12:15:48.271851Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

php-svg-lib is an SVG file parsing / rendering library. Prior to version 0.5.1, when parsing the attributes passed to a use tag inside an svg document, an attacker can cause the system to go to an infinite recursion. Depending on the system configuration and attack pattern this could exhaust the memory available to the executing process and/or to the server itself. An attacker sending multiple request to a system to render the above payload can potentially cause resource exhaustion to the point that the system is unable to handle incoming request. Version 0.5.1 contains a patch for this issue.

References

Affected packages

Git / github.com/dompdf/php-svg-lib

Affected ranges

Type
GIT
Repo
https://github.com/dompdf/php-svg-lib
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

0.*

0.3.4
0.4.0
0.4.1
0.5.0

v0.*

v0.1
v0.2
v0.3
v0.3.0
v0.3.1
v0.3.2
v0.3.3