๐Ÿ” CVE Alert

CVE-2026-107378

UNKNOWN 0.0

CairoSVG: Quadratic-time DoS parsing a crafted SVG <path>

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to 2.9.1, rendering an attacker-controlled SVG with a path containing many segments can cause quadratic CPU consumption in cairosvg/path.py. The path tokenizer repeatedly slices and rescans the remaining path data, while draw_markers drains node.vertices with node.vertices.pop(0), causing repeated linear-time work. The svg2png, svg2pdf, and svg2ps APIs reach these operations during ordinary rendering, allowing a sub-megabyte SVG to consume substantial CPU and deny service to a rendering application. This issue is fixed in version 2.9.1.

CWE CWE-407
Vendor kozea
Product cairosvg
Published Oct 8, 2026
Last Updated Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for kozea cairosvg

Be the first to know when new unknown vulnerabilities affecting kozea cairosvg are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Kozea / CairoSVG
< 2.9.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Kozea/CairoSVG/security/advisories/GHSA-c3jg-qh8m-j3h2 github.com: https://github.com/Kozea/CairoSVG/commit/9d63f049f9988d0ddda3eb94564ac3a50a286523 github.com: https://github.com/Kozea/CairoSVG/commit/a4d585eb374724b79676e9cceaa9e9a1a4358565 github.com: https://github.com/Kozea/CairoSVG/releases/tag/2.9.1