Denial of Service Risk in CairoSVG SVG Converter by Kozea
CVE-2026-107378

8.7HIGH

Key Information:

Vendor

Kozea

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107378?

CairoSVG versions prior to 2.9.1 are vulnerable to denial of service attacks due to an inefficient handling of SVG paths. When an attacker submits a specially crafted SVG file containing a path with many segments, it triggers excessive CPU usage during rendering. This is caused by the path tokenizer continuously slicing and rescanning the path data, leading to significant resource drain. The svg2png, svg2pdf, and svg2ps APIs are particularly susceptible as they engage in these operations during normal rendering processes, resulting in potential service disruptions. Users are advised to upgrade to version 2.9.1 or later to mitigate this risk.

Affected Version(s)

CairoSVG < 2.9.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.