Skip to content

fix: Fix for the CVE-2026-29072 vulerability in svgo (node.js docs gen) - #196

Merged
pbukva merged 2 commits into
merge/v0.53.x_to_v0.19.4from
fix/CVE-2026-29074_vulnerability
May 7, 2026
Merged

fix: Fix for the CVE-2026-29072 vulerability in svgo (node.js docs gen)#196
pbukva merged 2 commits into
merge/v0.53.x_to_v0.19.4from
fix/CVE-2026-29074_vulnerability

Conversation

@pbukva

@pbukva pbukva commented May 7, 2026

Copy link
Copy Markdown
Contributor

SVGO DoS through entity expansion in DOCTYPE (Billion Laughs)

  • High severity
  • GitHub Reviewed
  • Published on Mar 4 in svg/svgo

GHSA-xpqw-6gx7-v673

@pbukva
pbukva requested a review from MissingNO57 May 7, 2026 15:17
@pbukva pbukva self-assigned this May 7, 2026
@pbukva
pbukva changed the base branch from merge/v0.53.x_to_v0.19.4 to main May 7, 2026 15:22
…nearion)

SVGO DoS through entity expansion in DOCTYPE (Billion Laughs)
* High severity
* GitHub Reviewed
* Published on Mar 4 in svg/svgo
GHSA-xpqw-6gx7-v673
Comment thread testutil/network/network.go Dismissed
Comment thread server/util.go Dismissed
Comment thread server/util.go Dismissed
Comment thread server/start.go Dismissed
Comment thread crypto/keys/secp256k1/secp256k1.go Dismissed
Comment thread baseapp/oe/optimistic_execution.go Dismissed
Comment thread internal/conv/string.go Dismissed
Comment thread internal/conv/string.go Dismissed
Comment thread internal/conv/string.go Dismissed
Comment thread internal/conv/string.go Dismissed
Comment thread api/cosmos/autocli/v1/query.pulsar.go Dismissed
Comment thread api/cosmos/autocli/v1/query.pulsar.go Dismissed
Comment thread api/cosmos/autocli/v1/query.pulsar.go Dismissed
protoiface "google.golang.org/protobuf/runtime/protoiface"
protoimpl "google.golang.org/protobuf/runtime/protoimpl"
io "io"
reflect "reflect"
protoiface "google.golang.org/protobuf/runtime/protoiface"
protoimpl "google.golang.org/protobuf/runtime/protoimpl"
io "io"
reflect "reflect"
protoiface "google.golang.org/protobuf/runtime/protoiface"
protoimpl "google.golang.org/protobuf/runtime/protoimpl"
io "io"
reflect "reflect"
protoimpl "google.golang.org/protobuf/runtime/protoimpl"
descriptorpb "google.golang.org/protobuf/types/descriptorpb"
io "io"
reflect "reflect"
protoimpl "google.golang.org/protobuf/runtime/protoimpl"
anypb "google.golang.org/protobuf/types/known/anypb"
io "io"
reflect "reflect"
protoiface "google.golang.org/protobuf/runtime/protoiface"
protoimpl "google.golang.org/protobuf/runtime/protoimpl"
io "io"
reflect "reflect"
Comment thread api/amino/amino.pulsar.go
protoreflect "google.golang.org/protobuf/reflect/protoreflect"
protoimpl "google.golang.org/protobuf/runtime/protoimpl"
descriptorpb "google.golang.org/protobuf/types/descriptorpb"
reflect "reflect"
@pbukva
pbukva changed the base branch from main to merge/v0.53.x_to_v0.19.4 May 7, 2026 17:06
@pbukva
pbukva merged commit bea12aa into merge/v0.53.x_to_v0.19.4 May 7, 2026
44 of 51 checks passed
@pbukva
pbukva deleted the fix/CVE-2026-29074_vulnerability branch May 7, 2026 17:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants