Disclosure summary
CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to 2.9.1, rendering an attacker-controlled SVG with a path containing many segments can cause quadratic CPU consumption in cairosvg/path.py. The path tokenizer repeatedly slices and rescans the remaining path data, while draw_markers drains node.vertices with node.vertices.pop(0), causing repeated linear-time work. The svg2png, svg2pdf, and svg2ps APIs reach these operations during ordinary rendering, allowing a sub-megabyte SVG to consume substantial CPU and deny service to a rendering application. This issue is fixed in version 2.9.1.
Source-reported weakness categories
CWE-407
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2026-107378
Open original source · Updated Oct 08, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
GitHub Reviewed Security Advisories · GHSA-c3jg-qh8m-j3h2
Open original source · Updated Oct 08, 2026
CairoSVG: Quadratic-time DoS parsing a crafted SVG
Source severity: HIGH / 8.7
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| pip | cairosvg | 2.9.1 |
Original records & references
PUBLISHED 2026-10-08T14:17:23-04:00
MODIFIED 2026-10-08T17:33:42-04:00
INGESTED 2026-10-10T20:55:03-04:00