High severity7.5NVD Advisory· Published Nov 11, 2019· Updated Jun 17, 2026
CVE-2019-18856
CVE-2019-18856
Description
A Denial Of Service vulnerability exists in the SVG Sanitizer module through 8.x-1.0-alpha1 for Drupal because access to external resources with an SVG use element is mishandled.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:drupal:svg_sanitizer:*:*:*:*:*:drupal:*:*+ 2 more
- cpe:2.3:a:drupal:svg_sanitizer:*:*:*:*:*:drupal:*:*range: <=7.x-1.5
- cpe:2.3:a:drupal:svg_sanitizer:8.x-1.0:alpha1:*:*:*:drupal:*:*
- (no CPE)range: <=8.x-1.0-alpha1
- Drupal/SVG Sanitizerdescription
Patches
Vulnerability mechanics
References
2- git.drupalcode.org/project/svg_sanitizer/commit/e1b0666nvdPatchThird Party Advisory
- fortiguard.com/zeroday/FG-VD-19-115nvdThird Party Advisory
News mentions
0No linked articles in our index yet.