High severity8.7NVD Advisory· Published Oct 8, 2026· Updated Oct 8, 2026
CVE-2026-107378
CVE-2026-107378
Description
CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to 2.9.1, rendering an attacker-controlled SVG with a path containing many segments can cause quadratic CPU consumption in cairosvg/path.py. The path tokenizer repeatedly slices and rescans the remaining path data, while draw_markers drains node.vertices with node.vertices.pop(0), causing repeated linear-time work. The svg2png, svg2pdf, and svg2ps APIs reach these operations during ordinary rendering, allowing a sub-megabyte SVG to consume substantial CPU and deny service to a rendering application. This issue is fixed in version 2.9.1.
Affected products
2Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-c3jg-qh8m-j3h2ghsaADVISORY
- github.com/Kozea/CairoSVG/commit/9d63f049f9988d0ddda3eb94564ac3a50a286523nvd
- github.com/Kozea/CairoSVG/commit/a4d585eb374724b79676e9cceaa9e9a1a4358565nvd
- github.com/Kozea/CairoSVG/releases/tag/2.9.1nvd
- github.com/Kozea/CairoSVG/security/advisories/GHSA-c3jg-qh8m-j3h2nvd
- nvd.nist.gov/vuln/detail/CVE-2026-107378ghsa
News mentions
0No linked articles in our index yet.