CVE-2026-107378
Received Received - Intake

Denial of Service in CairoSVG via Path Processing

Vulnerability report for CVE-2026-107378, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to 2.9.1, rendering an attacker-controlled SVG with a path containing many segments can cause quadratic CPU consumption in cairosvg/path.py. The path tokenizer repeatedly slices and rescans the remaining path data, while draw_markers drains node.vertices with node.vertices.pop(0), causing repeated linear-time work. The svg2png, svg2pdf, and svg2ps APIs reach these operations during ordinary rendering, allowing a sub-megabyte SVG to consume substantial CPU and deny service to a rendering application. This issue is fixed in version 2.9.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Kozea CairoSVG < 2.9.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-407 An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CairoSVG before 2.9.1 has a denial-of-service vulnerability in path rendering. Attackers can craft SVGs with many path segments to cause quadratic CPU consumption. The path tokenizer repeatedly processes path data inefficiently, and draw_markers drains vertices in a slow way. This allows small SVGs to consume excessive CPU resources during normal rendering operations.

Detection Guidance

Detecting this vulnerability requires checking the CairoSVG version in use. Run: pip show cairosvg. If the version is below 2.9.1, the system is vulnerable. Additionally, monitor for unusual CPU usage spikes when processing SVG files, which may indicate exploitation attempts.

Impact Analysis

If you use CairoSVG versions before 2.9.1, an attacker could send a specially crafted SVG file that causes your system to use excessive CPU resources. This could slow down or crash your application, making it unresponsive. It may also affect other services running on the same system due to high resource usage.

Compliance Impact

This vulnerability could impact compliance by causing service disruptions or downtime, potentially violating availability requirements in GDPR or HIPAA. High CPU usage may also lead to performance degradation, affecting system reliability and data processing capabilities required by these regulations.

Mitigation Strategies

Upgrade CairoSVG to version 2.9.1 or later immediately. Use: pip install --upgrade cairosvg. If upgrading is not possible, restrict access to SVG processing functions or implement input validation to limit path complexity in SVG files.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107378. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart