PatchSiren

darylldoyle CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM darylldoyle CVE published 2026-10-08

CVE-2026-107379

A crafted SVG file crashes the PHP process when sanitized by `enshrined/svg-sanitize` (versions through 0.22.x) due to a type confusion bug in the sanitizer's `cleanAttributesOnWhitelist()` method. This issue affects multiple projects, including WordPress Safe SVG plugin, TYPO3, and Drupal. The vulnerability is triggered when the sanitizer attempts to remove attributes from an SVG file, causing a denial-o [truncated]

MEDIUM darylldoyle CVE published 2026-10-08

CVE-2026-107380

A vulnerability in the enshrined/svg-sanitize PHP library, known as svg-sanitizer, allows for stored XSS via DTD entity and HTML5 named character reference collision. The issue arises from the library's handling of SVG href attributes after XML DTD entity expansion and during inline HTML rendering. Specifically, the isHrefSafeValue() function validates an SVG href after XML DTD entity expansion, but saveX [truncated]