CVE-2026-29074: CWE-776: Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') in svg svgo
SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 2.1.0 to before version 2.8.1, from version 3.0.0 to before version 3.3.3, and before version 4.0.1, SVGO accepts XML with custom entities, without guards against entity expansion or recursion. This can result in a small XML file (811 bytes) stalling the application and even crashing the Node.js process with JavaScript heap out of memory. This issue has been patched in versions 2.8.1, 3.3.3, and 4.0.1.
AI Analysis
Technical Summary
CVE-2026-29074 is a denial of service vulnerability in SVGO caused by improper restriction of recursive entity references in XML DTDs (CWE-776). SVGO versions 2.1.0 through before 2.8.1, 3.0.0 through before 3.3.3, and all versions before 4.0.1 accept XML input with custom entities without guarding against entity expansion or recursion. This can lead to exponential data expansion, consuming excessive memory and crashing the Node.js process. The vulnerability is addressed in SVGO versions 2.8.1, 3.3.3, and 4.0.1. Red Hat advisories confirm the impact and provide details on affected products and mitigation status.
Potential Impact
An attacker can cause a denial of service by submitting a crafted XML file that triggers recursive entity expansion, leading to high memory consumption and crashing the Node.js process running SVGO. There is no impact on confidentiality or integrity, but availability is severely affected.
Mitigation Recommendations
Official patches are available in SVGO versions 2.8.1, 3.3.3, and 4.0.1. Users should upgrade to these or later versions to remediate the vulnerability. The Red Hat advisory notes that no alternative mitigations meet their criteria for ease of use and applicability, so upgrading is the recommended action.
CVE-2026-29074: CWE-776: Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') in svg svgo
Description
SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 2.1.0 to before version 2.8.1, from version 3.0.0 to before version 3.3.3, and before version 4.0.1, SVGO accepts XML with custom entities, without guards against entity expansion or recursion. This can result in a small XML file (811 bytes) stalling the application and even crashing the Node.js process with JavaScript heap out of memory. This issue has been patched in versions 2.8.1, 3.3.3, and 4.0.1.
CVSS v3.1
Score 7.5high
Affected software
svg
svgo
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-29074 is a denial of service vulnerability in SVGO caused by improper restriction of recursive entity references in XML DTDs (CWE-776). SVGO versions 2.1.0 through before 2.8.1, 3.0.0 through before 3.3.3, and all versions before 4.0.1 accept XML input with custom entities without guarding against entity expansion or recursion. This can lead to exponential data expansion, consuming excessive memory and crashing the Node.js process. The vulnerability is addressed in SVGO versions 2.8.1, 3.3.3, and 4.0.1. Red Hat advisories confirm the impact and provide details on affected products and mitigation status.
Potential Impact
An attacker can cause a denial of service by submitting a crafted XML file that triggers recursive entity expansion, leading to high memory consumption and crashing the Node.js process running SVGO. There is no impact on confidentiality or integrity, but availability is severely affected.
Mitigation Recommendations
Official patches are available in SVGO versions 2.8.1, 3.3.3, and 4.0.1. Users should upgrade to these or later versions to remediate the vulnerability. The Red Hat advisory notes that no alternative mitigations meet their criteria for ease of use and applicability, so upgrading is the recommended action.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-03-03T20:51:43.482Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-29074","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:13512","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:6277","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:7110","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:13553","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:6309","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:13545","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:9742","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:13826","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:5807","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:24977","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:19712","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:21772","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:8483","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:8484","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:8490","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:8491","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:8493","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:11856","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:21017","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:6568","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:19375","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:22465","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:11916","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:6926","vendor":"Red Hat"}]
Threat ID: 69aa82b7c48b3f10ff296e5d
Added to database: 03/06/2026, 07:31:03 UTC
Last enriched: 08/14/2026, 14:41:24 UTC
Last updated: 09/14/2026, 22:11:27 UTC
Views: 307
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.