CVE-2023-46035
The svg_optimizer gem before 0.3.0 for Ruby performs entity expansion on untrusted documents.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.9
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.36%
- CWE
- CWE-776
- Published
- 2026-09-14
- Last modified
- 2026-09-14
Affected products
- fnando svg_optimizer
Weakness type
Related vulnerabilities
- CVE-2021-32623 — Opencast vulnerable to billion laughs attack (XML bomb)
- CVE-2023-38490 — Kirby XML External Entity (XXE) vulnerability in the XML data handler
- CVE-2023-28118 — kaml has potential denial of service while parsing input with anchors and aliases
- CVE-2026-33036 — fast-xml-parser affected by numeric entity expansion bypassing all entity expansion limits (incomplete fix for CVE-2026-26278)
- CVE-2025-3225 — XML Entity Expansion vulnerability in run-llama/llama_index
- CVE-2026-78681 — NLTK before 3.10.3 Entity Expansion DoS via ElementTree
- CVE-2026-73569 — fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits
- CVE-2026-45304 — Symfony: YAML Parser Exponential Memory Allocation via Recursive Collection-Alias Expansion ("Billion Laughs")