CVE-2017-5617: Debian Linux

High severity, CVSS 7.4. EPSS: 2% chance of exploitation in the next 30 days.

The SVG Salamander (aka svgSalamander) library, when used in a web application, allows remote attackers to conduct server-side request forgery (SSRF) attacks via an xlink:href attribute in an SVG file.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Kitfox Svg Salamander: affected versions not specified

Published 2017-03-16. Last modified 2026-06-17.