Get real-time updates on Telegram
CVE-2026-105708: imgproxy 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.5, 4.0.6, 4.0.7, 4.0.8, 4.0.9, 4.0.10, 4.0.11, 4.0.12, 4.0.13, 4.0.14, 4.0.15, 4.0.16, 4.0.17
CVE-2026-105708. CVSS 2.0 base score 5.0 (MEDIUM, Vendor/CNA).
Affected technology
imgproxy · 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.5, 4.0.6, 4.0.7, 4.0.8, 4.0.9, 4.0.10, 4.0.11, 4.0.12, 4.0.13, 4.0.14, 4.0.15, 4.0.16, 4.0.17
Vendor not specified by the source
Description’s affected range: up to 4.0.17
Component: SVG Handler
Function: sanitizeElement
File: processing/svg/svg.go
Attack conditions (VulDB, CVSS 4.0): Network (remote) · No privileges required · Passive user interaction
What an attacker can do
VulDB’s CVSS 4.0 assessment (base score 2.1/10) rates confidentiality and availability impact as none; integrity impact as low. The description does not specify what an attacker can achieve beyond these rated impacts.
- CWE
- CWE-79, CWE-94
- CCR priority
- 20.0 /100 (P4)
- CVSS 2.0
- 5.0 /10 · CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:P/A:N · Vendor/CNA
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-06 06:29:43.409280+00:00 UTC
- GitHub Advisory Database · Source record · observed 2026-10-06 06:45:50.992780+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-105708.html