Your message dated Sat, 03 Oct 2026 05:48:56 +0000
with message-id <[email protected]>
and subject line Bug#1149715: fixed in node-svgo 3.3.5+ds-1
has caused the Debian Bug report #1149715,
regarding node-svgo: CVE-2026-29074 CVE-2026-73650 CVE-2026-84369 CVE-2026-84370
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1149715: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1149715
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: node-svgo
Version: 3.3.2+ds-1
X-Debbugs-CC: [email protected]
Severity: important
Tags: security upstream
Hi,
The following vulnerabilities were published for node-svgo.
CVE-2026-29074[0]:
| SVGO, short for SVG Optimizer, is a Node.js library and command-line
| application for optimizing SVG files. From version 2.1.0 to before
| version 2.8.1, from version 3.0.0 to before version 3.3.3, and
| before version 4.0.1, SVGO accepts XML with custom entities, without
| guards against entity expansion or recursion. This can result in a
| small XML file (811 bytes) stalling the application and even
| crashing the Node.js process with JavaScript heap out of memory.
| This issue has been patched in versions 2.8.1, 3.3.3, and 4.0.1.
CVE-2026-73650[1]:
| SVGO, short for SVG Optimizer, is a Node.js library and command-line
| application for optimizing SVG files. From version 1.0.0 until
| versions 2.8.3, 3.3.4, and 4.0.2, the removeScripts plugin, named
| removeScriptElement in versions 1 through 3, can leave executable
| content in optimized SVGs because it does not remove namespaced or
| prefixed script elements such as <svg:script> and, in versions 3 and
| 4, matches JavaScript URIs case sensitively. Applications that
| process untrusted SVG input with this plugin enabled and serve the
| result can allow scripts to execute when another user opens the SVG,
| exposing local storage or cookies. This issue is fixed in versions
| 2.8.3, 3.3.4, and 4.0.2.
CVE-2026-84369[2]:
| SVGO, short for SVG Optimizer, is a Node.js library and command-line
| application for optimizing SVG files. From version 1.0.0 until
| versions 2.8.4, 3.3.5, and 4.1.0, the opt-in removeScripts plugin,
| named removeScriptElement in versions 2 and 3 and implemented in
| plugins/removeScripts.js, removes SVG and XHTML script elements but
| does not inspect executable HTML content inside SVG foreignObject
| elements. Event-handler attributes such as onload and
| onbeforetoggle, srcdoc documents, and executable URLs in the action,
| data, formaction, href, and src attributes can remain in attacker-
| controlled SVG input. When an application uses the plugin as its
| only protection and serves the optimized SVG in an active browser
| context, the payload can execute script in the viewer's origin,
| expose data, modify content, or perform actions as the victim. This
| issue is fixed in versions 2.8.4, 3.3.5, and 4.1.0.
CVE-2026-84370[3]:
| SVGO, short for SVG Optimizer, is a Node.js library and command-line
| application for optimizing SVG files. From version 1.0.0 until
| versions 2.8.4, 3.3.5, and 4.1.0, the opt-in removeScripts plugin,
| named removeScriptElement in versions 2 and 3, incompletely filters
| executable links in plugins/removeScripts.js and lib/svgo/tools.js.
| The plugin does not recognize namespace-prefixed SVG anchor elements
| such as svg:a with href or namespaced *:href values, and it does not
| remove ASCII tab, line-feed, or carriage-return characters before
| checking URL schemes. Browsers remove those characters before
| parsing a scheme, allowing an executable link to pass the plugin's
| check. When an application processes attacker-controlled SVG input
| and serves the result in an active browser context, a victim who
| activates the surviving link can execute script in the SVG's origin,
| expose data, modify content, or perform actions as the victim. This
| issue is fixed in versions 2.8.4, 3.3.5, and 4.1.0.
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-29074
https://www.cve.org/CVERecord?id=CVE-2026-29074
[1] https://security-tracker.debian.org/tracker/CVE-2026-73650
https://www.cve.org/CVERecord?id=CVE-2026-73650
[2] https://security-tracker.debian.org/tracker/CVE-2026-84369
https://www.cve.org/CVERecord?id=CVE-2026-84369
[3] https://security-tracker.debian.org/tracker/CVE-2026-84370
https://www.cve.org/CVERecord?id=CVE-2026-84370
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: node-svgo
Source-Version: 3.3.5+ds-1
Done: Xavier Guimard <[email protected]>
We believe that the bug you reported is fixed in the latest version of
node-svgo, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Xavier Guimard <[email protected]> (supplier of updated node-svgo package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sat, 03 Oct 2026 07:29:37 +0200
Source: node-svgo
Architecture: source
Version: 3.3.5+ds-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Javascript Maintainers
<[email protected]>
Changed-By: Xavier Guimard <[email protected]>
Closes: 1149715
Changes:
node-svgo (3.3.5+ds-1) unstable; urgency=medium
.
* Team upload
* New upstream version (Closes: #1149715, CVE-2026-29074 CVE-2026-73650
CVE-2026-84369 CVE-2026-84370)
* Add dependency to node-sax
Checksums-Sha1:
ad75b15909cfced409bc454da39dadc919019772 2150 node-svgo_3.3.5+ds-1.dsc
bea393ddb3304cb74ba6adcf55d7bac1e3a1fa40 197072 node-svgo_3.3.5+ds.orig.tar.xz
2374bdcca48b8c3aff30eccdf2271e6ea81edc9f 2832
node-svgo_3.3.5+ds-1.debian.tar.xz
Checksums-Sha256:
d13f6841564625d98fd88faffde3b8245c47e5bb0a687c3a88abfd360ec483de 2150
node-svgo_3.3.5+ds-1.dsc
4a04cac89c0d00deade1d68a56d6996dab897bca5975d0dffe546973c78a3577 197072
node-svgo_3.3.5+ds.orig.tar.xz
3915061a81ffd2c60b71ae439f52917b7adb0ca1ca67ca74b4da8c5dab420e94 2832
node-svgo_3.3.5+ds-1.debian.tar.xz
Files:
4de8909c1d5bd3952af2146976a2d5bb 2150 javascript optional
node-svgo_3.3.5+ds-1.dsc
1dbf3ccdcf82654cad19dc6e8e8a5cde 197072 javascript optional
node-svgo_3.3.5+ds.orig.tar.xz
edb6fa6e72b40b894eb7ccbbf34dc693 2832 javascript optional
node-svgo_3.3.5+ds-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmrAkw4ACgkQ9tdMp8mZ
7ulOOQ//VDLjld2xUyMbCZGSmjM5fGvA71mHnePsPgi0KyI9awG26n3NJ70RvASg
2k/P69NvSLz6dBH92eenFx4IbQzpUKiY+ywHQKeJfKRu8FaP0PLOJpKBZzCSlXef
UFIILO+NmrnKUHGPCg67C3QPM2OTDipAmANFFeGIbdoa1CIbspGO+8V0EXd1ToE0
lVSbTAh3pcPR7qYg4RKPv4N7wBFQmSBdtTIo5TkaAk1WGn9ymMCNw9gbSleaemdy
/hndCuu7HlXps6IH/7/1eHQawxEr41lkMJSGlgqo9WYB/Vs4HfW3EFBeABHcLKiI
uyF3kJENBCi7pId3DOFkz9+4z9LjJNuXetYVjJy85EcSex8nJo+s8WY9gyt2y2Ks
MHOKvAPBQyNyJyb+O18RPPpmVxYQpdGN5xA9Q1z88xXQKzzTsQAPIXaw91av+II6
8P4OJCjBKiZ+1pJAiKl3X/7avN31Kj9eJMD3cmKHoApzif7UDM0qY+qJOHXCH7qy
n+ukGEfUN5dObSEJzYpSK+bbMqlu3ZobScF6l949uM8rfPqSr0e1e1IlU4qdvoTM
iaw6upOrGWq3AoX5VXA55X1Hf2x/TqGGl3qfBXmL8LTsRjzxLvRn+t2/9mCLRGWl
hSd/hqTXgv4VSHGNVln1tJ4rGTCLyJ0MdUtWus9ABdjk5whACzA=
=EWbj
-----END PGP SIGNATURE-----
pgpUVEm00ypIT.pgp
Description: PGP signature
--- End Message ---
--
Pkg-javascript-devel mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel