---
id: CVE-2022-44729
title: >-
  Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation
  Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16.


  On version 1.16, a malicious SVG could trigger loading external resources by
  de…
summary: >-
  Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation
  Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16.


  On version 1.16, a malicious SVG could trigger loading external resources by
  de…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H'
cwe:
  - CWE-918
vendor: apache
product: xml_graphics_batik
affected:
  - 'xml_graphics_batik >= 1.0, <= 1.16'
  - debian_linux = 10.0
published: '2023-08-22'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:17:22.090'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-44729'
references:
  - url: 'http://www.openwall.com/lists/oss-security/2023/08/22/2'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2023/08/22/4'
    label: security@apache.org
  - url: 'https://lists.apache.org/thread/hco2nw1typoorz33qzs0fcdx0ws6d6j2'
    label: security@apache.org
  - url: 'https://lists.debian.org/debian-lts-announce/2023/10/msg00021.html'
    label: security@apache.org
  - url: 'https://security.gentoo.org/glsa/202401-11'
    label: security@apache.org
  - url: 'https://xmlgraphics.apache.org/security.html'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2023/08/22/2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2023/08/22/4'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.apache.org/thread/hco2nw1typoorz33qzs0fcdx0ws6d6j2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2023/10/msg00021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.gentoo.org/glsa/202401-11'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://xmlgraphics.apache.org/security.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00919
epssPercentile: 0.59052
ingestedAt: '2026-10-08T23:16:47.351Z'
---

## Overview

Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16.

On version 1.16, a malicious SVG could trigger loading external resources by default, causing resource consumption or in some cases even information disclosure. Users are recommended to upgrade to version 1.17 or later.

## Affected

- `xml_graphics_batik >= 1.0, <= 1.16`
- `debian_linux = 10.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
