Exponential Denial of Service in CairoSVG by Kozea
CVE-2026-31899
7.5HIGH
Key Information:
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-31899?
CairoSVG, an SVG converter based on the Cairo 2D graphics library, has a vulnerability that allows for exponential denial of service. This occurs via recursive amplification of the element within the cairosvg/defs.py file. A small input can lead to excessive CPU consumption, potentially overwhelming the system's processing capabilities. Users are advised to review the advisory for mitigation steps.
Affected Version(s)
CairoSVG < 2.9.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
