CVE-2026-107381: svg-sanitizer: Mixed-case xlink:HrEf skips the `<use>` nesting-DoS check in Resolver::processReferences
Resolver::processReferences() collects <use> elements with the XPath predicate use[@href or @xlink:href], which is case sensitive. A <use> element written as xlink:HrEf is therefore never added to the reference graph, so the nesting-DoS nullification never marks it for removal. Sanitizer::cleanHrefAttributes() then runs later in the same pass and rewrites xlink:HrEf back to the canonical xlink:href. The sanitizer hands back a fully live nesting bomb that it would have stripped completely had the input used canonical casing.
This is the mirror image of CVE-2025-55166: that fix made href value checking case insensitive, but the <use> reference graph still selects nodes case sensitively.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-107381 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →