WhisperX tag archive

#CVE-2026-29074

This page collects WhisperX intelligence signals tagged #CVE-2026-29074. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (2)

The Lab · 2026-04-01 13:27:16 · GitHub Issues

1. SVGO v4.0.1 Security Patch: XML Entity Attack Can Crash Node.js Applications

A critical security flaw in the popular SVG optimization tool SVGO exposes thousands of web applications to denial-of-service attacks. The vulnerability, tracked as CVE-2026-29074, allows a maliciously crafted XML file as small as 811 bytes to stall an application and crash the underlying Node.js process with a 'JavaSc...

The Lab · 2026-04-01 19:27:38 · GitHub Issues

2. SVGO XML Parser Vulnerability (CVE-2026-29074): Small File Can Crash Node.js Processes

A critical vulnerability in the popular SVG optimization tool SVGO allows a maliciously crafted, tiny XML file to crash applications and exhaust Node.js memory. The flaw, tracked as CVE-2026-29074, stems from the tool's underlying XML parser accepting custom entities without proper safeguards against entity expansion o...