<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 21:01:21 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-384746</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-384746</link>
      <description>EUVD-2026-384746</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-384746</guid>
    </item>
    <item>
      <title>fkie_cve-2026-107380</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-107380</link>
      <description>&lt;p&gt;savg-sanitizer is a PHP SVG/XML sanitizer. Prior to 1.0.0, svg-sanitizer&amp;#39;s isHrefSafeValue() validates an SVG href after XML DTD entity expansion, but saveXML() serializes the original entity reference after removing the DTD declaration. A crafted entity such as Tab can appear to the sanitizer as a safe fragment prefix while HTML5 Named Character Reference resolution during inline HTML rendering later converts the surviving reference to whitespace, exposing a javascript: URL. When an application embeds the sanitized SVG inline, a user who activates the link can cause script to execute in the embedding page&amp;#39;s origin. This issue is fixed in version 1.0.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;savg-sanitizer is a PHP SVG/XML sanitizer. Prior to 1.0.0, svg-sanitizer&amp;#39;s isHrefSafeValue() validates an SVG href after XML DTD entity expansion, but saveXML() serializes the original entity reference after removing the DTD declaration. A crafted entity such as Tab can appear to the sanitizer as a safe fragment prefix while HTML5 Named Character Reference resolution during inline HTML rendering later converts the surviving reference to whitespace, exposing a javascript: URL. When an application embeds the sanitized SVG inline, a user who activates the link can cause script to execute in the embedding page&amp;#39;s origin. This issue is fixed in version 1.0.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-107380</guid>
    </item>
    <item>
      <title>GHSA-9rjx-3jch-6vjf — enshrined/svg-sanitize: Stored XSS via DTD Entity / HTML5 Named Character Reference Collision</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9rjx-3jch-6vjf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: enshrined/svg-sanitize&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A crafted SVG bypasses `enshrined/svg-sanitize`&amp;#39;s href validation and delivers a `javascript:` URL through the sanitizer unchanged. The bypass exploits a semantic mismatch between XML entity resolution (used during sanitization) and HTML5 Named Character Reference resolution (used by the browser when the SVG is rendered inline).&lt;/p&gt;
&lt;p&gt;**This is a logic bug in svg-sanitize. It does NOT depend on any PHP ext/dom bug — it works on any PHP version.**&lt;/p&gt;
&lt;p&gt;**Affected installations:**
- **enshrined/svg-sanitize:** 45.2M Packagist downloads, 1.3M/month, 90+ dependents
- **WordPress Safe SVG plugin:** 1M+ active installs (inline SVG rendering via themes)
- **TYPO3, Drupal** and 90+ other Packagist dependents&lt;/p&gt;
&lt;p&gt;## Vulnerability Details&lt;/p&gt;
&lt;p&gt;### Mechanism&lt;/p&gt;
&lt;p&gt;1. Attacker defines a DTD entity whose name collides with an HTML5 Named Character Reference:
   ```xml
   &amp;lt;!ENTITY Tab &amp;#34;#&amp;#34;&amp;gt;
   ```
   In XML, `&amp;amp;Tab;` expands to the literal string `&amp;#34;#&amp;#34;` (from the DTD definition).
   In HTML5, `&amp;amp;Tab;` is a Named Character Reference that resolves to U+0009 (TAB character).&lt;/p&gt;
&lt;p&gt;2. The SVG uses this entity in an href:
   ```xml
   &amp;lt;a href=&amp;#34;&amp;amp;Tab;javascript:alert(document.domain)&amp;#34;&amp;gt;
   ```&lt;/p&gt;
&lt;p&gt;3. **During sanitization** (XML context): `&amp;amp;Tab;` → `&amp;#34;#&amp;#34;` → the sanitizer sees `href=&amp;#34;#javascript:alert(document.domain)&amp;#34;` → starts with `#` → `isHrefSafeValue()` returns **TRUE** → passes through.&lt;/p&gt;
&lt;p&gt;4. **Sanitizer output:** `saveXML()` outputs the entity reference `&amp;amp;Tab;` (not the expanded value), and strips the DOCTYPE dec…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: enshrined/svg-sanitize&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A crafted SVG bypasses `enshrined/svg-sanitize`&amp;#39;s href validation and delivers a `javascript:` URL through the sanitizer unchanged. The bypass exploits a semantic mismatch between XML entity resolution (used during sanitization) and HTML5 Named Character Reference resolution (used by the browser when the SVG is rendered inline).&lt;/p&gt;
&lt;p&gt;**This is a logic bug in svg-sanitize. It does NOT depend on any PHP ext/dom bug — it works on any PHP version.**&lt;/p&gt;
&lt;p&gt;**Affected installations:**
- **enshrined/svg-sanitize:** 45.2M Packagist downloads, 1.3M/month, 90+ dependents
- **WordPress Safe SVG plugin:** 1M+ active installs (inline SVG rendering via themes)
- **TYPO3, Drupal** and 90+ other Packagist dependents&lt;/p&gt;
&lt;p&gt;## Vulnerability Details&lt;/p&gt;
&lt;p&gt;### Mechanism&lt;/p&gt;
&lt;p&gt;1. Attacker defines a DTD entity whose name collides with an HTML5 Named Character Reference:
   ```xml
   &amp;lt;!ENTITY Tab &amp;#34;#&amp;#34;&amp;gt;
   ```
   In XML, `&amp;amp;Tab;` expands to the literal string `&amp;#34;#&amp;#34;` (from the DTD definition).
   In HTML5, `&amp;amp;Tab;` is a Named Character Reference that resolves to U+0009 (TAB character).&lt;/p&gt;
&lt;p&gt;2. The SVG uses this entity in an href:
   ```xml
   &amp;lt;a href=&amp;#34;&amp;amp;Tab;javascript:alert(document.domain)&amp;#34;&amp;gt;
   ```&lt;/p&gt;
&lt;p&gt;3. **During sanitization** (XML context): `&amp;amp;Tab;` → `&amp;#34;#&amp;#34;` → the sanitizer sees `href=&amp;#34;#javascript:alert(document.domain)&amp;#34;` → starts with `#` → `isHrefSafeValue()` returns **TRUE** → passes through.&lt;/p&gt;
&lt;p&gt;4. **Sanitizer output:** `saveXML()` outputs the entity reference `&amp;amp;Tab;` (not the expanded value), and strips the DOCTYPE dec…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9rjx-3jch-6vjf</guid>
    </item>
  </channel>
</rss>
