<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 23:31:21 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-00530</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-00530</link>
      <description>bdu:2023-00530</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-00530</guid>
    </item>
    <item>
      <title>EUVD-2026-221624</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-221624</link>
      <description>EUVD-2026-221624</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-221624</guid>
    </item>
    <item>
      <title>fkie_cve-2023-23924</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-23924</link>
      <description>&lt;p&gt;Dompdf is an HTML to PDF converter. The URI validation on dompdf 2.0.1 can be bypassed on SVG parsing by passing `&amp;lt;image&amp;gt;` tags with uppercase letters. This may lead to arbitrary object unserialize on PHP &amp;lt; 8, through the `phar` URL wrapper. An attacker can exploit the vulnerability to call arbitrary URL with arbitrary protocols, if they can provide a SVG file to dompdf. In PHP versions before 8.0.0, it leads to arbitrary unserialize, that will lead to the very least to an arbitrary file deletion and even remote code execution, depending on classes that are available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Dompdf is an HTML to PDF converter. The URI validation on dompdf 2.0.1 can be bypassed on SVG parsing by passing `&amp;lt;image&amp;gt;` tags with uppercase letters. This may lead to arbitrary object unserialize on PHP &amp;lt; 8, through the `phar` URL wrapper. An attacker can exploit the vulnerability to call arbitrary URL with arbitrary protocols, if they can provide a SVG file to dompdf. In PHP versions before 8.0.0, it leads to arbitrary unserialize, that will lead to the very least to an arbitrary file deletion and even remote code execution, depending on classes that are available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-23924</guid>
    </item>
    <item>
      <title>GHSA-3cw5-7cxw-v5qg — Dompdf vulnerable to URI validation failure on SVG parsing</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3cw5-7cxw-v5qg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: dompdf/dompdf&lt;/p&gt;
&lt;p&gt;### Summary
The URI validation on dompdf 2.0.1 can be bypassed on SVG parsing by passing `&amp;lt;image&amp;gt;` tags with uppercase letters. This might leads to arbitrary object unserialize on PHP &amp;lt; 8, through the `phar` URL wrapper.&lt;/p&gt;
&lt;p&gt;### Details
The bug occurs during SVG parsing of `&amp;lt;image&amp;gt;` tags, in src/Image/Cache.php :&lt;/p&gt;
&lt;p&gt;```
if ($type === &amp;#34;svg&amp;#34;) {
    $parser = xml_parser_create(&amp;#34;utf-8&amp;#34;);
    xml_parser_set_option($parser, XML_OPTION_CASE_FOLDING, false);
    xml_set_element_handler(
        $parser,
        function ($parser, $name, $attributes) use ($options, $parsed_url, $full_url) {
            if ($name === &amp;#34;image&amp;#34;) {
                $attributes = array_change_key_case($attributes, CASE_LOWER);
```
This part will try to detect `&amp;lt;image&amp;gt;` tags in SVG, and will take the href to validate it against the protocolAllowed whitelist. However, the `$name comparison with &amp;#34;image&amp;#34; is case sensitive, which means that such a tag in the SVG will pass :&lt;/p&gt;
&lt;p&gt;```
&amp;lt;svg&amp;gt;
    &amp;lt;Image xlink:href=&amp;#34;phar:///foo&amp;#34;&amp;gt;&amp;lt;/Image&amp;gt;
&amp;lt;/svg&amp;gt;
```&lt;/p&gt;
&lt;p&gt;As the tag is named &amp;#34;Image&amp;#34; and not &amp;#34;image&amp;#34;, it will not pass the condition to trigger the check.&lt;/p&gt;
&lt;p&gt;A correct solution would be to strtolower the `$name` before the check :&lt;/p&gt;
&lt;p&gt;```
if (strtolower($name) === &amp;#34;image&amp;#34;) {
```&lt;/p&gt;
&lt;p&gt;### PoC
Parsing the following SVG file is sufficient to reproduce the vulnerability :&lt;/p&gt;
&lt;p&gt;```
&amp;lt;svg&amp;gt;
    &amp;lt;Image xlink:href=&amp;#34;phar:///foo&amp;#34;&amp;gt;&amp;lt;/Image&amp;gt;
&amp;lt;/svg&amp;gt;
```&lt;/p&gt;
&lt;p&gt;### Impact
An attacker might be able to exploit the vulnerability to call arbitrary URL with arbitrary protoc…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: dompdf/dompdf&lt;/p&gt;
&lt;p&gt;### Summary
The URI validation on dompdf 2.0.1 can be bypassed on SVG parsing by passing `&amp;lt;image&amp;gt;` tags with uppercase letters. This might leads to arbitrary object unserialize on PHP &amp;lt; 8, through the `phar` URL wrapper.&lt;/p&gt;
&lt;p&gt;### Details
The bug occurs during SVG parsing of `&amp;lt;image&amp;gt;` tags, in src/Image/Cache.php :&lt;/p&gt;
&lt;p&gt;```
if ($type === &amp;#34;svg&amp;#34;) {
    $parser = xml_parser_create(&amp;#34;utf-8&amp;#34;);
    xml_parser_set_option($parser, XML_OPTION_CASE_FOLDING, false);
    xml_set_element_handler(
        $parser,
        function ($parser, $name, $attributes) use ($options, $parsed_url, $full_url) {
            if ($name === &amp;#34;image&amp;#34;) {
                $attributes = array_change_key_case($attributes, CASE_LOWER);
```
This part will try to detect `&amp;lt;image&amp;gt;` tags in SVG, and will take the href to validate it against the protocolAllowed whitelist. However, the `$name comparison with &amp;#34;image&amp;#34; is case sensitive, which means that such a tag in the SVG will pass :&lt;/p&gt;
&lt;p&gt;```
&amp;lt;svg&amp;gt;
    &amp;lt;Image xlink:href=&amp;#34;phar:///foo&amp;#34;&amp;gt;&amp;lt;/Image&amp;gt;
&amp;lt;/svg&amp;gt;
```&lt;/p&gt;
&lt;p&gt;As the tag is named &amp;#34;Image&amp;#34; and not &amp;#34;image&amp;#34;, it will not pass the condition to trigger the check.&lt;/p&gt;
&lt;p&gt;A correct solution would be to strtolower the `$name` before the check :&lt;/p&gt;
&lt;p&gt;```
if (strtolower($name) === &amp;#34;image&amp;#34;) {
```&lt;/p&gt;
&lt;p&gt;### PoC
Parsing the following SVG file is sufficient to reproduce the vulnerability :&lt;/p&gt;
&lt;p&gt;```
&amp;lt;svg&amp;gt;
    &amp;lt;Image xlink:href=&amp;#34;phar:///foo&amp;#34;&amp;gt;&amp;lt;/Image&amp;gt;
&amp;lt;/svg&amp;gt;
```&lt;/p&gt;
&lt;p&gt;### Impact
An attacker might be able to exploit the vulnerability to call arbitrary URL with arbitrary protoc…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3cw5-7cxw-v5qg</guid>
    </item>
    <item>
      <title>gsd-2023-23924</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-23924</link>
      <description>gsd-2023-23924</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-23924</guid>
    </item>
  </channel>
</rss>
