---
id: CVE-2026-29074
title: >-
  SVGO, short for SVG Optimizer, is a Node.js library and command-line
  application for optimizing SVG files
summary: >-
  SVGO, short for SVG Optimizer, is a Node.js library and command-line
  application for optimizing SVG files. From version 2.1.0 to before version
  2.8.1, from version 3.0.0 to before version 3.3.3, and before version 4.0.1,
  SVGO accepts XML…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-776
vendor: svgo
product: svgo
affected:
  - 'svgo >= 2.1.0, < 2.8.1'
  - 'svgo >= 3.0.0, < 3.3.3'
  - 'svgo >= 4.0.0, < 4.0.1'
patched:
  - svgo 4.0.1
published: '2026-03-06'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T13:18:03.533'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-29074'
references:
  - url: 'https://github.com/svg/svgo/security/advisories/GHSA-xpqw-6gx7-v673'
    label: security-advisories@github.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:11856'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:11916'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:13512'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:13545'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:13553'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:13826'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:19375'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:19712'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:21017'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:21772'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:22465'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:24977'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:48085'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:5807'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:6277'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:6309'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:6568'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:6926'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:7110'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:8483'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:8484'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:8490'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:8491'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:8493'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:9742'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-29074'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2445132'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-29074.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-29074'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-29074'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-03-06T15:59:57.009864Z'
epss: 0.00612
epssPercentile: 0.47989
ingestedAt: '2026-07-01T15:50:58.584Z'
---

## Overview

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 2.1.0 to before version 2.8.1, from version 3.0.0 to before version 3.3.3, and before version 4.0.1, SVGO accepts XML with custom entities, without guards against entity expansion or recursion. This can result in a small XML file (811 bytes) stalling the application and even crashing the Node.js process with JavaScript heap out of memory. This issue has been patched in versions 2.8.1, 3.3.3, and 4.0.1.

## Affected

- `svgo >= 2.1.0, < 2.8.1`
- `svgo >= 3.0.0, < 3.3.3`
- `svgo >= 4.0.0, < 4.0.1`

## Remediation

Upgrade past the affected range:

- `svgo 4.0.1`

## Vendor advisories

- **RHSA-2026:13512** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 · released 2026-05-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:13512)
- **RHSA-2026:6277** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2026-03-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:6277)
- **RHSA-2026:7110** · Red Hat · fixed in: Red Hat Advanced Cluster Security 4.8 · released 2026-04-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:7110)
- **RHSA-2026:13553** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 · released 2026-05-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:13553)
- **RHSA-2026:6309** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 · released 2026-03-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:6309)
- **RHSA-2026:13545** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 · released 2026-05-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:13545)
- **RHSA-2026:9742** · Red Hat · fixed in: Red Hat Developer Hub 1.8 · released 2026-04-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:9742)
- **RHSA-2026:13826** · Red Hat · fixed in: Red Hat Developer Hub 1.9 · released 2026-05-05 · [advisory](https://access.redhat.com/errata/RHSA-2026:13826)
- **RHSA-2026:5807** · Red Hat · fixed in: Red Hat OpenShift AI 2.16 · released 2026-03-25 · [advisory](https://access.redhat.com/errata/RHSA-2026:5807)
- **RHSA-2026:24977** · Red Hat · fixed in: Red Hat OpenShift AI 2.25 · released 2026-06-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:24977)
- **RHSA-2026:19712** · Red Hat · fixed in: Red Hat OpenShift AI 3.3 · released 2026-05-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:19712)
- **Red Hat VEX** · Important · affected: Cryostat 4, OpenShift Pipelines, Red Hat 3scale API Management Platform 2, Red Hat Ansible Automation Platform 2, Red Hat build of Apicurio Registry 2, Red Hat Data Grid 8, … · no fix planned: OpenShift Pipelines, Red Hat 3scale API Management Platform 2, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Fuse 7, … · updated 2026-09-09 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-29074.json)
