CairoSVG Quadratic-Time Denial of Service
CairoSVG versions 2.9.0 and earlier are vulnerable to a CPU-exhaustion denial-of-service attack due to O(n²) complexity in SVG path-data parsing and marker rendering.
CVE search metadata
CVE search record: CVE-2026-107378. KEV: no. Product: CairoSVG (<= 2.9.0). Brief: CairoSVG Quadratic-Time Denial of Service. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cairosvg-dos/
CairoSVG versions 2.9.0 and earlier contain two independent O(n²) performance bottlenecks that can be exploited by an attacker to conduct a denial-of-service (DoS) attack against applications rendering untrusted SVG documents. The vulnerability exists within cairosvg/path.py in the path-data tokenizer and the marker handling logic. The tokenizer consumes path strings using a loop that repeatedly re-slices the remaining string, leading to quadratic time complexity. Simultaneously, the marker rendering function utilizes list.pop(0) to drain vertices, which is an O(n) operation in Python, also resulting in O(n²) complexity.
An attacker can trigger this vulnerability by submitting a specially crafted SVG document with a high density of path segments. Testing demonstrates that a document under 1 MiB can consume approximately 18 seconds of CPU time. This makes any web service that utilizes CairoSVG to process user-supplied SVG files, such as those generating thumbnails, avatars, or PDF exports, highly susceptible to resource exhaustion attacks.
Impact
The impact of this vulnerability is a high-availability risk for services relying on CairoSVG for image processing. By repeatedly sending these crafted SVG documents, an attacker can effectively pin CPU cores, leading to service degradation or total outage. This affects any application performing server-side rendering of user-provided content.
Recommendation
- Upgrade to a version of CairoSVG that includes the fix for CVE-2026-107378.
- Implement input validation on the server side to limit the number of segments allowed in a single
<path>element before processing. - Enforce strict timeouts on image rendering jobs to mitigate the impact of CPU-intensive operations on the application server.
Immediate actions
Upgrade CairoSVG to 2.9.1 or later
Mitigations
Implement length and segment count validation for SVG uploads prior to calling CairoSVG rendering APIs.
CVE-2026-107378