<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T08:24:12.996402+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-384745</id>
    <title>EUVD-2026-384745</title>
    <updated>2026-10-10T08:24:12.998600+00:00</updated>
    <content>EUVD-2026-384745</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-384745"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-107379</id>
    <title>fkie_cve-2026-107379</title>
    <updated>2026-10-10T08:24:12.998633+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>savg-sanitizer is a PHP SVG/XML sanitizer. Prior to 1.0.0, svg-sanitizer allows a crafted SVG DTD with a #FIXED attribute default to make cleanAttributesOnWhitelist() perform a double DOMElement::removeAttribute() call on the same attribute name in src/Sanitizer.php. The first removal deletes the explicit attribute, while the DTD default rematerializes the value before the href safety path performs the second removal, which can corrupt libxml state and terminate the PHP worker. An attacker who can submit SVG content to a sanitization endpoint can repeatedly interrupt workers and degrade or exhaust application availability. This issue is fixed in version 1.0.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-107379"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-v383-3rw5-q8rf</id>
    <title>GHSA-v383-3rw5-q8rf — enshrined/svg-sanitize: Denial of Service via DTD Attribute Declaration Crash</title>
    <updated>2026-10-10T08:24:12.998672+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: enshrined/svg-sanitize</p>
<p>## Summary</p>
<p>A crafted SVG file (1009 bytes) crashes the PHP process when sanitized by `enshrined/svg-sanitize` (any version through 0.22.x). The sanitizer's `cleanAttributesOnWhitelist()` method calls `DOMElement::removeAttribute()` twice on the same attribute name — first removing the explicit attribute, then attempting to remove the DTD `#FIXED` default — triggering a PHP ext/dom type confusion that kills the PHP-FPM worker.</p>
<p>**Affected installations:**
- **enshrined/svg-sanitize:** 45.2M Packagist downloads, 1.3M/month, 90+ dependents
- **WordPress Safe SVG plugin:** 1M+ active installs
- **TYPO3:** svg-sanitize integrated into core since v9
- **Drupal:** community module wrapping svg-sanitize</p>
<p>## Vulnerability Details</p>
<p>### Trigger Flow</p>
<p>```
Sanitizer::sanitize($malicious_svg)
  → DOMDocument::loadXML() — parses DTD, creates XML_ATTRIBUTE_DECL for #FIXED attr
  → startClean() → cleanAttributesOnWhitelist($svgElement)
    → "badhref" NOT in allowedAttrs
    → removeAttribute("badhref")          ← removes explicit attribute (safe)
    → stripos("badhref", "href") = TRUE
    → getAttribute("badhref")             ← returns DTD #FIXED default value
    → isHrefSafeValue("javascript:x")    ← returns FALSE
    → removeAttribute("badhref")          ← hits XML_ATTRIBUTE_DECL → CRASH
```</p>
<p>**Root cause in svg-sanitize:** The sanitizer does not strip DOCTYPE/DTD declarations before processing. The `cleanAttributesOnWhitelist()` method at `Sanitizer.php:303-330` has a double-removal p…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-v383-3rw5-q8rf"/>
  </entry>
</feed>
