VYPR

svg-sanitizer

by Enshrined

CVEs (1)

  • CVE-2026-107381Oct 8, 2026
    risk 0.00cvss —epss —

    ## Summary `Resolver::processReferences()` collects `` elements with the XPath predicate `use[@href or @xlink:href]`, which is case sensitive. A `` element written as `xlink:HrEf` is therefore never added to the reference graph, so the nesting-DoS nullification never…