Entity Expansion Vulnerability in svg_optimizer Gem for Ruby
CVE-2023-46035

5.9MEDIUM

Key Information:

Vendor

Fnando

Vendor
CVE Published:
14 September 2026

What is CVE-2023-46035?

The svg_optimizer gem for Ruby, prior to version 0.3.0, is susceptible to an entity expansion vulnerability. This flaw arises when the gem processes untrusted documents, potentially allowing an attacker to exploit the system by manipulating entity expansion. The risk is primarily associated with parsing user-controlled input, which can lead to unexpected resource consumption or even denial of service conditions. It is crucial to update to version 0.3.0 or later to mitigate this vulnerability.

Affected Version(s)

svg_optimizer 0 < 0.3.0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.