{"success":true,"data":{"threats":[{"id":"93ee4c14-2fae-4123-89b4-a35e42c2668f","slug":"cve-2026-107378","externalId":"CVE-2026-107378","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107378 — CairoSVG is an SVG converter based on Cairo, a 2D graphics library.","description":"CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to 2.9.1, rendering an attacker-controlled SVG with a path containing many segments can cause quadratic CPU consumption in cairosvg/path.py. The path tokenizer repeatedly slices and rescans the remaining path data, while draw_markers drains node.vertices with node.vertices.pop(0), causing repeated linear-time work. The svg2png, svg2pdf, and svg2ps APIs reach these operations during ordinary rendering, allowing a sub-megabyte SVG to consume substantial CPU and deny service to a rendering application. This issue is fixed in version 2.9.1.","cveId":"CVE-2026-107378","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":"PyPI","product":"cairosvg","affectedVersions":["pkg:pypi/cairosvg < 2.9.1"],"cwes":["CWE-407"],"tags":["nvd","status:received","osv","osv:ghsa-c3jg-qh8m-j3h2","ecosystem:pypi","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/Kozea/CairoSVG/commit/9d63f049f9988d0ddda3eb94564ac3a50a286523","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/Kozea/CairoSVG/commit/a4d585eb374724b79676e9cceaa9e9a1a4358565","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/Kozea/CairoSVG/releases/tag/2.9.1","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/Kozea/CairoSVG/security/advisories/GHSA-c3jg-qh8m-j3h2","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://osv.dev/vulnerability/GHSA-c3jg-qh8m-j3h2","type":"advisory","title":"OSV GHSA-c3jg-qh8m-j3h2"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107378","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/Kozea/CairoSVG","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T18:17:23.417Z","addedAt":"2026-10-08T18:39:31.903Z","updatedAt":"2026-10-08T23:06:38.820Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107378","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107378","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-C3JG-QH8M-J3H2"}]}],"pagination":{"page":1,"limit":20,"total":1,"totalPages":1,"hasNext":false,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-09T00:04:10.407Z","durationMs":7,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":["osv:ghsa-c3jg-qh8m-j3h2"],"cwe":[],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}