CVE-2016-9181: Image-Info Project Image-Info For Perl

High severity, CVSS 7.1. EPSS: 1.2% chance of exploitation in the next 30 days.

perl-Image-Info: When parsing an SVG file, external entity expansion (XXE) was not disabled. An attacker could craft an SVG file which, when processed by an application using perl-Image-Info, could cause denial of service or, potentially, information disclosure.

Affected products

Published 2016-12-22. Last modified 2026-06-17.