Disclosure summary
## Summary `Resolver::processReferences()` collects `` elements with the XPath predicate `use[@href or @xlink:href]`, which is case sensitive. A `` element written as `xlink:HrEf` is therefore never added to the reference graph, so the nesting-DoS nullification never marks it for removal. `Sanitizer::cleanHrefAttributes()` then runs later in the same pass and rewrites `xlink:HrEf` back to the canonical `xlink:href`. The sanitizer hands back a fully live nesting bomb that it would have stripped completely had the input used canonical casing. This is the mirror image of CVE-2025-55166: that fix made href *value* checking case insensitive, but the `` reference graph still selects nodes case sensitively. ## Where it is `src/ElementReference/Resolver.php:97-118`, the case-sensitive node selection: ```php $useNodeName = $this->xPath->createNodeName('use'); foreach ($this->subjects as $subject) { $useElements = $this->xPath->query( $useNodeName . '[@href or @xlink:href]', $subject->getElement() ); ``` `src/Sanitizer.php:479-504`, the normalization that happens afterwards and makes the attribute live again: ```php // in case the attribute name is `HrEf`/`xlink:HrEf`, adjust it to `href`/`x
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-m9xh-6747-9r6f
Open original source · Updated Oct 08, 2026
svg-sanitizer: Mixed-case xlink:HrEf skips the `` nesting-DoS check in Resolver::processReferences
Source severity: MEDIUM / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| composer | enshrined/svg-sanitize | 1.0.0 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-08T15:41:10-04:00
MODIFIED 2026-10-08T15:41:11-04:00
INGESTED 2026-10-10T20:25:13-04:00