Denial of Service Risk in CairoSVG SVG Converter by Kozea
CVE-2026-107378
8.7HIGH
What is CVE-2026-107378?
CairoSVG versions prior to 2.9.1 are vulnerable to denial of service attacks due to an inefficient handling of SVG paths. When an attacker submits a specially crafted SVG file containing a path with many segments, it triggers excessive CPU usage during rendering. This is caused by the path tokenizer continuously slicing and rescanning the path data, leading to significant resource drain. The svg2png, svg2pdf, and svg2ps APIs are particularly susceptible as they engage in these operations during normal rendering processes, resulting in potential service disruptions. Users are advised to upgrade to version 2.9.1 or later to mitigate this risk.
Affected Version(s)
CairoSVG < 2.9.1
