Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

Yes, SVGs are XML-based and may be vulnerable to generic XML-based XML external entity (XXE) or exponential entity expansion attacks, but this particular malicious SVG is using SVG-specific features to create the resource exhaustion.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: