CVE-2026-107378 — CairoSVG is an SVG converter based on Cairo, a 2D graphics library.
Description
CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to 2.9.1, rendering an attacker-controlled SVG with a path containing many segments can cause quadratic CPU consumption in cairosvg/path.py. The path tokenizer repeatedly slices and rescans the remaining path data, while draw_markers drains node.vertices with node.vertices.pop(0), causing repeated linear-time work. The svg2png, svg2pdf, and svg2ps APIs reach these operations during ordinary rendering, allowing a sub-megabyte SVG to consume substantial CPU and deny service to a rendering application. This issue is fixed in version 2.9.1.
CVSS v4.0 base metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XHigh severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
AT
None
Attack Requirements
PR
None
Privileges Required
UI
None
User Interaction
VC
None
Confidentiality (Vulnerable System)
VI
None
Integrity (Vulnerable System)
VA
High
Availability (Vulnerable System)
SC
None
Confidentiality (Subsequent System)
SI
None
Integrity (Subsequent System)
SA
None
Availability (Subsequent System)
Affected
- Vendor
- PyPI
- Product
- cairosvg
Versions
- pkg:pypi/cairosvg < 2.9.1
Stated as the source expressed them.
References
- otherOSV webhttps://github.com/Kozea/CairoSVG/commit/9d63f049f9988d0ddda3eb94564ac3a50a286523
- otherOSV webhttps://github.com/Kozea/CairoSVG/commit/a4d585eb374724b79676e9cceaa9e9a1a4358565
- otherOSV webhttps://github.com/Kozea/CairoSVG/releases/tag/2.9.1
- otherOSV webhttps://github.com/Kozea/CairoSVG/security/advisories/GHSA-c3jg-qh8m-j3h2
- advisoryOSV GHSA-c3jg-qh8m-j3h2https://osv.dev/vulnerability/GHSA-c3jg-qh8m-j3h2
- advisoryOSV advisoryhttps://nvd.nist.gov/vuln/detail/CVE-2026-107378
- vendorOSV packagehttps://github.com/Kozea/CairoSVG
Related threats
same CWE or vendorPraisonAI: Prompt-injection defense blocks only when 3+ detector families fire simultaneously; realistic single-vector injections pass through unblocked
CVE-2026-60086 · 3h ago
PraisonAI: API deploy code generator embeds unescaped YAML fields into Python source
CVE-2026-61433 · 3h ago
PraisonAI: Call API localhost-only authentication bypass via spoofed Host header
CVE-2026-61435 · 3h ago
CVE-2026-107377 — datamodel-code-generator generates Python data models from schema definitions.
CVE-2026-107377 · 4h ago
PraisonAI: ContextGatherer include resolution permits absolute and traversal reads outside the workspace
CVE-2026-61431 · 5h ago
PraisonAI: Project custom command templates can read outside-workspace files into model prompts
CVE-2026-60088 · 5h ago