SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 2.1.0 to before version 2.8.1, from version 3.0.0 to before version 3.3.3, and before version 4.0.1, SVGO accepts XML with custom entities, without guards against entity expansion or recursion. This can result in a small XML file (811 bytes) stalling the application and even crashing the Node.js process with JavaScript heap out of memory. This issue has been patched in versions 2.8.1, 3.3.3, and 4.0.1.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-xpqw-6gx7-v673 SVGO DoS through entity expansion in DOCTYPE (Billion Laughs)
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
https://access.redhat.com/errata/RHSA-2026:11856 cve-icon
https://access.redhat.com/errata/RHSA-2026:11916 cve-icon
https://access.redhat.com/errata/RHSA-2026:13512 cve-icon
https://access.redhat.com/errata/RHSA-2026:13545 cve-icon
https://access.redhat.com/errata/RHSA-2026:13553 cve-icon
https://access.redhat.com/errata/RHSA-2026:13826 cve-icon
https://access.redhat.com/errata/RHSA-2026:19375 cve-icon
https://access.redhat.com/errata/RHSA-2026:19712 cve-icon
https://access.redhat.com/errata/RHSA-2026:21017 cve-icon
https://access.redhat.com/errata/RHSA-2026:21772 cve-icon
https://access.redhat.com/errata/RHSA-2026:22465 cve-icon
https://access.redhat.com/errata/RHSA-2026:24977 cve-icon
https://access.redhat.com/errata/RHSA-2026:48085 cve-icon
https://access.redhat.com/errata/RHSA-2026:5807 cve-icon
https://access.redhat.com/errata/RHSA-2026:6277 cve-icon
https://access.redhat.com/errata/RHSA-2026:6309 cve-icon
https://access.redhat.com/errata/RHSA-2026:6568 cve-icon
https://access.redhat.com/errata/RHSA-2026:6926 cve-icon
https://access.redhat.com/errata/RHSA-2026:7110 cve-icon
https://access.redhat.com/errata/RHSA-2026:8483 cve-icon
https://access.redhat.com/errata/RHSA-2026:8484 cve-icon
https://access.redhat.com/errata/RHSA-2026:8490 cve-icon
https://access.redhat.com/errata/RHSA-2026:8491 cve-icon
https://access.redhat.com/errata/RHSA-2026:8493 cve-icon
https://access.redhat.com/errata/RHSA-2026:9742 cve-icon
https://access.redhat.com/security/cve/CVE-2026-29074 cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2445132 cve-icon
https://github.com/svg/svgo/security/advisories/GHSA-xpqw-6gx7-v673 cve-icon cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2026-29074 cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-29074.json cve-icon
https://www.cve.org/CVERecord?id=CVE-2026-29074 cve-icon
History

Sat, 14 Mar 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Tue, 10 Mar 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Svgo
Svgo svgo
CPEs cpe:2.3:a:svgo:svgo:*:*:*:*:*:node.js:*:*
Vendors & Products Svgo
Svgo svgo

Fri, 06 Mar 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 06 Mar 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Svg
Svg svgo
Vendors & Products Svg
Svg svgo

Fri, 06 Mar 2026 07:30:00 +0000

Type Values Removed Values Added
Description SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 2.1.0 to before version 2.8.1, from version 3.0.0 to before version 3.3.3, and before version 4.0.1, SVGO accepts XML with custom entities, without guards against entity expansion or recursion. This can result in a small XML file (811 bytes) stalling the application and even crashing the Node.js process with JavaScript heap out of memory. This issue has been patched in versions 2.8.1, 3.3.3, and 4.0.1.
Title SVGO: DoS through entity expansion in DOCTYPE (Billion Laughs)
Weaknesses CWE-776
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-12T12:04:41.889Z

Reserved: 2026-03-03T20:51:43.482Z

Link: CVE-2026-29074

cve-icon Vulnrichment

Updated: 2026-08-12T12:04:41.889Z

cve-icon NVD

Status : Modified

Published: 2026-03-06T08:16:26.920

Modified: 2026-08-12T12:18:23.830

Link: CVE-2026-29074

cve-icon Redhat

Severity : Important

Publid Date: 2026-03-06T07:23:05Z

Links: CVE-2026-29074 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T11:30:15Z

Weaknesses