You are viewing this page in an unauthorized frame window.
This is a potential security issue, you are being redirected to
https://nvd.nist.gov
An official website of the United States government
Official websites use .gov
A .gov website belongs to an official government organization in the United States.
Secure .gov websites use HTTPS
A lock () or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.
An improper neutralization of active SVG content in OTRS or ((OTRS)) Community Edition ticket article rendering allows attackers to inject specially crafted SVG payloads via email content, leading to browser-side resource exhaustion and denial of service when affected tickets are opened by an agent or customer. The issue can be exploited without JavaScript execution and is not mitigated by the configured Content Security Policy (CSP).
This issue affects OTRS:
* 7.0.X
* 8.0.X
* 2023.X
* 2024.X
* 2025.X
* 2026.X before 2026.4.X
Please note that ((OTRS)) Community Edition 6.x and before are vulnerable. Products based on the ((OTRS)) Community Edition also very likely to be affected
Metrics
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [email protected].
Title: OTRS AG, Description: Una neutralización inadecuada de contenido SVG activo en la representación de artículos de tickets de OTRS o ((OTRS)) Community Edition permite a los atacantes inyectar cargas útiles SVG especialmente diseñadas a través del contenido del correo electrónico, lo que lleva al agotamiento de recursos del lado del navegador y a la denegación de servicio cuando los tickets afectados son abiertos por un agente o cliente. El problema puede ser explotado sin ejecución de JavaScript y no es mitigado por la Política de Seguridad de Contenido (CSP) configurada.
Este problema afecta a OTRS:
* 7.0.X
* 8.0.X
* 2023.X
* 2024.X
* 2025.X
* 2026.X antes de 2026.4.X
Tenga en cuenta que ((OTRS)) Community Edition 6.x y versiones anteriores son vulnerables. Los productos basados en ((OTRS)) Community Edition también son muy propensos a ser afectados.
[{"vendor":"OTRS AG","product":"OTRS","defaultStatus":"affected","modules":["Agent Frontend","External Interface"],"versions":[{"version":"7.0.x","status":"affected"},{"version":"8.0.x","status":"affected"},{"version":"2023.x","status":"affected"},{"version":"2024.x","status":"affected"},{"version":"2025.x","status":"affected"},{"version":"2026.x","lessThanOrEqual":"2026.3.x","versionType":"patch","status":"affected"}]},{"vendor":"OTRS AG","product":"((OTRS)) Community Edition","defaultStatus":"affected","modules":["Agent Frontend","External Interface"],"versions":[{"version":"6.x","status":"affected"}]}]
Initial Analysis by NIST6/15/2026 8:39:37 AM
Action
Type
Old Value
New Value
Added
CPE Configuration
OR
*cpe:2.3:a:otrs:otrs:*:*:*:*:community:*:*:* versions up to (including) 6.0.32
*cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:* versions from (including) 7.0.0 up to (including) 8.0.37
*cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:* versions from (including) 2023.0.0 up to (excluding) 2026.4.1
Added
Reference Type
OTRS AG: https://otrs.com/release-notes/otrs-security-advisory-2026-07/ Types: Vendor Advisory
New CVE Received from OTRS AG6/01/2026 12:16:23 AM
Action
Type
Old Value
New Value
Added
Description
An improper neutralization of active SVG content in OTRS or ((OTRS)) Community Edition ticket article rendering allows attackers to inject specially crafted SVG payloads via email content, leading to browser-side resource exhaustion and denial of service when affected tickets are opened by an agent or customer. The issue can be exploited without JavaScript execution and is not mitigated by the configured Content Security Policy (CSP).
This issue affects OTRS:
* 7.0.X
* 8.0.X
* 2023.X
* 2024.X
* 2025.X
* 2026.X before 2026.4.X
Please note that ((OTRS)) Community Edition 6.x and before are vulnerable. Products based on the ((OTRS)) Community Edition also very likely to be affected