CVE-2026-29074: CWE-776: Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') in svg svgo
SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 2.1.0 to before version 2.8.1, from version 3.0.0 to before version 3.3.3, and before version 4.0.1, SVGO accepts XML with custom entities, without guards against entity expansion or recursion. This can result in a small XML file (811 bytes) stalling the application and even crashing the Node.js process with JavaScript heap out of memory. This issue has been patched in versions 2.8.1, 3.3.3, and 4.0.1.
AI Analysis
Technical Summary
CVE-2026-29074 is a denial-of-service vulnerability in SVGO, a Node.js SVG optimization tool, caused by improper restriction of recursive XML entity references in DTDs (CWE-776). Affected SVGO versions (>=2.1.0 <2.8.1, >=3.0.0 <3.3.3, and <4.0.1) accept XML input with custom entities without safeguards against entity expansion or recursion. This can lead to excessive memory consumption and crash the Node.js process. The vulnerability has been patched in versions 2.8.1, 3.3.3, and 4.0.1. Red Hat advisories provide official fixes for affected distributions embedding SVGO. The CVSS 3.1 vector indicates network attack vector, low complexity, no privileges or user interaction required, and impact limited to availability (score 7.5).
Potential Impact
The vulnerability allows an attacker to cause a denial of service by submitting a crafted SVG file containing recursive XML entity references. This can stall the SVGO application or crash the Node.js process due to JavaScript heap out of memory exhaustion. There is no impact on confidentiality or integrity. The disruption affects availability of services or applications using vulnerable SVGO versions.
Mitigation Recommendations
Official patches are available in SVGO versions 2.8.1, 3.3.3, and 4.0.1 that fix this vulnerability. Users should upgrade to these or later versions to remediate the issue. Red Hat has issued security advisories and errata providing updated packages that incorporate these fixes. Applying these vendor-provided updates is the recommended mitigation. No additional action is required if these versions or later are in use.
CVE-2026-29074: CWE-776: Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') in svg svgo
Description
SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 2.1.0 to before version 2.8.1, from version 3.0.0 to before version 3.3.3, and before version 4.0.1, SVGO accepts XML with custom entities, without guards against entity expansion or recursion. This can result in a small XML file (811 bytes) stalling the application and even crashing the Node.js process with JavaScript heap out of memory. This issue has been patched in versions 2.8.1, 3.3.3, and 4.0.1.
CVSS v3.1
Score 7.5high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-29074 is a denial-of-service vulnerability in SVGO, a Node.js SVG optimization tool, caused by improper restriction of recursive XML entity references in DTDs (CWE-776). Affected SVGO versions (>=2.1.0 <2.8.1, >=3.0.0 <3.3.3, and <4.0.1) accept XML input with custom entities without safeguards against entity expansion or recursion. This can lead to excessive memory consumption and crash the Node.js process. The vulnerability has been patched in versions 2.8.1, 3.3.3, and 4.0.1. Red Hat advisories provide official fixes for affected distributions embedding SVGO. The CVSS 3.1 vector indicates network attack vector, low complexity, no privileges or user interaction required, and impact limited to availability (score 7.5).
Potential Impact
The vulnerability allows an attacker to cause a denial of service by submitting a crafted SVG file containing recursive XML entity references. This can stall the SVGO application or crash the Node.js process due to JavaScript heap out of memory exhaustion. There is no impact on confidentiality or integrity. The disruption affects availability of services or applications using vulnerable SVGO versions.
Mitigation Recommendations
Official patches are available in SVGO versions 2.8.1, 3.3.3, and 4.0.1 that fix this vulnerability. Users should upgrade to these or later versions to remediate the issue. Red Hat has issued security advisories and errata providing updated packages that incorporate these fixes. Applying these vendor-provided updates is the recommended mitigation. No additional action is required if these versions or later are in use.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-03-03T20:51:43.482Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-29074","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:13512","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:6277","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:7110","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:13553","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:6309","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:13545","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:9742","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:13826","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:5807","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:24977","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:19712","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:21772","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:8483","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:8484","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:8490","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:8491","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:8493","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:11856","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:21017","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:6568","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:19375","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:22465","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:11916","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:6926","vendor":"Red Hat"}]
Threat ID: 69aa82b7c48b3f10ff296e5d
Added to database: 03/06/2026, 07:31:03 UTC
Last enriched: 07/30/2026, 01:38:18 UTC
Last updated: 07/31/2026, 21:26:43 UTC
Views: 279
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.