CairoSVG improperly processes SVG files loaded from external resources
CVE-2023-27586

9.9CRITICAL

Key Information:

Vendor

Kozea

Status
Vendor
CVE Published:
20 March 2023

What is CVE-2023-27586?

CairoSVG, an SVG converter utilizing the Cairo 2D graphics library, is vulnerable to a server-side request forgery due to its ability to make external requests while processing SVG files. Attackers can exploit this by sending crafted SVG files that compromise the server's response behavior, potentially leading to denial of service. The issue has been addressed in version 2.7.0, which disables external file access by default, enhancing security against such attacks.

Affected Version(s)

CairoSVG < 2.7.0

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.