Hacker News new | ask | show | jobs
by xml 2021 days ago
There are SVGs which will crash most browsers, so SVGs could still be abused for denial-of-service attacks.

For example, you could post one of those SVGs in every issue thread of a GitHub project if you wanted to mess with someone.

Not eligible for a bug bounty though since this issue has been known (but not fixed) for years.