1. SVGO v4.0.1 Security Patch: XML Entity Attack Can Crash Node.js Applications
A critical security flaw in the popular SVG optimization tool SVGO exposes thousands of web applications to denial-of-service attacks. The vulnerability, tracked as CVE-2026-29074, allows a maliciously crafted XML file as small as 811 bytes to stall an application and crash the underlying Node.js process with a 'JavaSc...