Is Svg Project maintains a narrowly scoped SVG processing library that, despite its modest disclosure footprint, sees use across visualization and web-rendering contexts where parser robustness matters. The observed vulnerabilities cluster around the structural demands of SVG handling, and current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Is Svg Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-28092HIGH The is-svg package 2.1.0 through 4.2.1 for Node.js uses a regular expression that is vulnerable to Regular Expression Denial of Service (ReDoS). If an attacker provides a malicious | Mar 12, 2021 | 7.5 | 25 | NO | NO |
CVE-2021-29059HIGH A vulnerability was discovered in IS-SVG version 2.1.0 to 4.2.2 and below where a Regular Expression Denial of Service (ReDOS) occurs if the application is provided and checks a cr | Jun 21, 2021 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Is Svg Project.
Media articles that mention a CVE ID that affects a product developed by Is Svg Project — matched by CVE ID, not by vendor name.