CVE-2022-44730: Apache XML Graphics Batik

Medium severity, CVSS 4.4. EPSS: 0.9% chance of exploitation in the next 30 days.

Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16. A malicious SVG can probe user profile / data and send it directly as parameter to a URL.

Affected products

  • Apache XML Graphics Batik: from 1.0, up to and including 1.16
  • Debian Debian Linux: version 10.0 only

Published 2023-08-22. Last modified 2026-06-17.