<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 08:23:44 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-384745</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-384745</link>
      <description>EUVD-2026-384745</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-384745</guid>
    </item>
    <item>
      <title>fkie_cve-2026-107379</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-107379</link>
      <description>&lt;p&gt;savg-sanitizer is a PHP SVG/XML sanitizer. Prior to 1.0.0, svg-sanitizer allows a crafted SVG DTD with a #FIXED attribute default to make cleanAttributesOnWhitelist() perform a double DOMElement::removeAttribute() call on the same attribute name in src/Sanitizer.php. The first removal deletes the explicit attribute, while the DTD default rematerializes the value before the href safety path performs the second removal, which can corrupt libxml state and terminate the PHP worker. An attacker who can submit SVG content to a sanitization endpoint can repeatedly interrupt workers and degrade or exhaust application availability. This issue is fixed in version 1.0.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;savg-sanitizer is a PHP SVG/XML sanitizer. Prior to 1.0.0, svg-sanitizer allows a crafted SVG DTD with a #FIXED attribute default to make cleanAttributesOnWhitelist() perform a double DOMElement::removeAttribute() call on the same attribute name in src/Sanitizer.php. The first removal deletes the explicit attribute, while the DTD default rematerializes the value before the href safety path performs the second removal, which can corrupt libxml state and terminate the PHP worker. An attacker who can submit SVG content to a sanitization endpoint can repeatedly interrupt workers and degrade or exhaust application availability. This issue is fixed in version 1.0.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-107379</guid>
    </item>
    <item>
      <title>GHSA-v383-3rw5-q8rf — enshrined/svg-sanitize: Denial of Service via DTD Attribute Declaration Crash</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v383-3rw5-q8rf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: enshrined/svg-sanitize&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A crafted SVG file (1009 bytes) crashes the PHP process when sanitized by `enshrined/svg-sanitize` (any version through 0.22.x). The sanitizer&amp;#39;s `cleanAttributesOnWhitelist()` method calls `DOMElement::removeAttribute()` twice on the same attribute name — first removing the explicit attribute, then attempting to remove the DTD `#FIXED` default — triggering a PHP ext/dom type confusion that kills the PHP-FPM worker.&lt;/p&gt;
&lt;p&gt;**Affected installations:**
- **enshrined/svg-sanitize:** 45.2M Packagist downloads, 1.3M/month, 90+ dependents
- **WordPress Safe SVG plugin:** 1M+ active installs
- **TYPO3:** svg-sanitize integrated into core since v9
- **Drupal:** community module wrapping svg-sanitize&lt;/p&gt;
&lt;p&gt;## Vulnerability Details&lt;/p&gt;
&lt;p&gt;### Trigger Flow&lt;/p&gt;
&lt;p&gt;```
Sanitizer::sanitize($malicious_svg)
  → DOMDocument::loadXML() — parses DTD, creates XML_ATTRIBUTE_DECL for #FIXED attr
  → startClean() → cleanAttributesOnWhitelist($svgElement)
    → &amp;#34;badhref&amp;#34; NOT in allowedAttrs
    → removeAttribute(&amp;#34;badhref&amp;#34;)          ← removes explicit attribute (safe)
    → stripos(&amp;#34;badhref&amp;#34;, &amp;#34;href&amp;#34;) = TRUE
    → getAttribute(&amp;#34;badhref&amp;#34;)             ← returns DTD #FIXED default value
    → isHrefSafeValue(&amp;#34;javascript:x&amp;#34;)    ← returns FALSE
    → removeAttribute(&amp;#34;badhref&amp;#34;)          ← hits XML_ATTRIBUTE_DECL → CRASH
```&lt;/p&gt;
&lt;p&gt;**Root cause in svg-sanitize:** The sanitizer does not strip DOCTYPE/DTD declarations before processing. The `cleanAttributesOnWhitelist()` method at `Sanitizer.php:303-330` has a double-removal p…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: enshrined/svg-sanitize&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A crafted SVG file (1009 bytes) crashes the PHP process when sanitized by `enshrined/svg-sanitize` (any version through 0.22.x). The sanitizer&amp;#39;s `cleanAttributesOnWhitelist()` method calls `DOMElement::removeAttribute()` twice on the same attribute name — first removing the explicit attribute, then attempting to remove the DTD `#FIXED` default — triggering a PHP ext/dom type confusion that kills the PHP-FPM worker.&lt;/p&gt;
&lt;p&gt;**Affected installations:**
- **enshrined/svg-sanitize:** 45.2M Packagist downloads, 1.3M/month, 90+ dependents
- **WordPress Safe SVG plugin:** 1M+ active installs
- **TYPO3:** svg-sanitize integrated into core since v9
- **Drupal:** community module wrapping svg-sanitize&lt;/p&gt;
&lt;p&gt;## Vulnerability Details&lt;/p&gt;
&lt;p&gt;### Trigger Flow&lt;/p&gt;
&lt;p&gt;```
Sanitizer::sanitize($malicious_svg)
  → DOMDocument::loadXML() — parses DTD, creates XML_ATTRIBUTE_DECL for #FIXED attr
  → startClean() → cleanAttributesOnWhitelist($svgElement)
    → &amp;#34;badhref&amp;#34; NOT in allowedAttrs
    → removeAttribute(&amp;#34;badhref&amp;#34;)          ← removes explicit attribute (safe)
    → stripos(&amp;#34;badhref&amp;#34;, &amp;#34;href&amp;#34;) = TRUE
    → getAttribute(&amp;#34;badhref&amp;#34;)             ← returns DTD #FIXED default value
    → isHrefSafeValue(&amp;#34;javascript:x&amp;#34;)    ← returns FALSE
    → removeAttribute(&amp;#34;badhref&amp;#34;)          ← hits XML_ATTRIBUTE_DECL → CRASH
```&lt;/p&gt;
&lt;p&gt;**Root cause in svg-sanitize:** The sanitizer does not strip DOCTYPE/DTD declarations before processing. The `cleanAttributesOnWhitelist()` method at `Sanitizer.php:303-330` has a double-removal p…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v383-3rw5-q8rf</guid>
    </item>
  </channel>
</rss>
