CVE-2026-48208 PUBLISHED

Denial-of-Service via SVG Rendering in Ticket

Assigner: OTRS
Reserved: 21.05.2026 Published: 01.06.2026 Updated: 01.06.2026

An improper neutralization of active SVG content in OTRS or ((OTRS)) Community Edition ticket article rendering allows attackers to inject specially crafted SVG payloads via email content, leading to browser-side resource exhaustion and denial of service when affected tickets are opened by an agent or customer. The issue can be exploited without JavaScript execution and is not mitigated by the configured Content Security Policy (CSP).

This issue affects OTRS:

  • 7.0.X
  • 8.0.X
  • 2023.X
  • 2024.X
  • 2025.X
  • 2026.X before 2026.4.X

Please note that ((OTRS)) Community Edition 6.x and before are vulnerable. Products based on the ((OTRS)) Community Edition also very likely to be affected

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS Score: 6.5

Product Status

Vendor OTRS AG
Product OTRS
Versions Default: affected
  • Version 7.0.x is affected
  • Version 8.0.x is affected
  • Version 2023.x is affected
  • Version 2024.x is affected
  • Version 2025.x is affected
  • affected from 2026.x to 2026.3.x (incl.)
Vendor OTRS AG
Product ((OTRS)) Community Edition
Versions Default: affected
  • Version 6.x is affected

Solutions

Update to OTRS 2026.4.1. or later. Please note that there will be no OTRS 7 patches

Credits

  • Special thanks to Daniel Triznafor reporting this vulnerability reporter

References

Problem Types

  • CWE-400 Uncontrolled Resource Consumption CWE
  • CWE-791 Incomplete Filtering of Special Elements CWE

Impacts

  • CAPEC-130 Excessive Allocation