#VU70328 Resource exhaustion in Loofah - CVE-2022-23514
Published: December 14, 2022
Loofah
Mike Dalessio
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when parsing certain SVG attributes. A remote attacker can pass a specially crafted SVG file to the application and consume excessive CPU resources, causing a denial of service (DoS) attack.