AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-107381.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 08, 2026

Disclosure summary

## Summary `Resolver::processReferences()` collects `` elements with the XPath predicate `use[@href or @xlink:href]`, which is case sensitive. A `` element written as `xlink:HrEf` is therefore never added to the reference graph, so the nesting-DoS nullification never marks it for removal. `Sanitizer::cleanHrefAttributes()` then runs later in the same pass and rewrites `xlink:HrEf` back to the canonical `xlink:href`. The sanitizer hands back a fully live nesting bomb that it would have stripped completely had the input used canonical casing. This is the mirror image of CVE-2025-55166: that fix made href *value* checking case insensitive, but the `` reference graph still selects nodes case sensitively. ## Where it is `src/ElementReference/Resolver.php:97-118`, the case-sensitive node selection: ```php $useNodeName = $this->xPath->createNodeName('use'); foreach ($this->subjects as $subject) { $useElements = $this->xPath->query( $useNodeName . '[@href or @xlink:href]', $subject->getElement() ); ``` `src/Sanitizer.php:479-504`, the normalization that happens afterwards and makes the attribute live again: ```php // in case the attribute name is `HrEf`/`xlink:HrEf`, adjust it to `href`/`x

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-m9xh-6747-9r6f

Open original source · Updated Oct 08, 2026

svg-sanitizer: Mixed-case xlink:HrEf skips the `` nesting-DoS check in Resolver::processReferences

Source severity: MEDIUM / 0

EcosystemPackageAffected rangeFirst patched
composerenshrined/svg-sanitize1.0.0

Original records & references

PUBLISHED 2026-10-08T15:41:10-04:00
MODIFIED 2026-10-08T15:41:11-04:00
INGESTED 2026-10-10T20:25:13-04:00