image/svg+xml
image/svg+xml is the type for SVG images. Unlike other image types, SVG is an XML document that can carry scripts and links, so how you serve it matters as much as the type itself.
Open in cURL Builder A request with this type is filled in.
Header
Content-Type: image/svg+xmlAt a glance
- Extensions
- .svg
- Kind
- Text
- Parameters
- None
- In a browser
- Renders the image. Opened directly rather than through
<img>, it is a document whose scripts run.
With curl
curl -o logo.svg -H 'Accept: image/svg+xml' https://example.com/logo.svg
With fetch
const res = await fetch('https://example.com/logo.svg');
const svg = await res.text(); // text, not a blob: SVG is XMLCommon mistakes
Uploaded SVG can run scripts
An SVG with
<script>or anonloadattribute, opened from your domain, runs with your cookies. Sanitize uploaded SVG, serve it withContent-Security-Policy: script-src 'none'or as an attachment, or convert it to PNG.The wrong type breaks
<img>Served as
text/xmlortext/plain, an SVG does not show in an<img>tag, which requiresimage/svg+xml.Compress it
SVG is text, so gzip or Brotli shrink it a lot. Check that your server compresses
image/svg+xml: nginx, for one, compresses onlytext/htmluntil you list more types ingzip_types.