<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:cairosvg:cairosvg:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3acairosvgcairosvg/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 08 Oct 2026 19:44:04 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3acairosvgcairosvg/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>CairoSVG Quadratic-Time Denial of Service</title><link>https://feed.craftedsignal.io/briefs/2026-10-cairosvg-dos/</link><pubDate>Thu, 08 Oct 2026 19:44:04 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-cairosvg-dos/</guid><description>CairoSVG versions 2.9.0 and earlier are vulnerable to a CPU-exhaustion denial-of-service attack due to O(n²) complexity in SVG path-data parsing and marker rendering.</description><content:encoded><![CDATA[<p>CairoSVG versions 2.9.0 and earlier contain two independent O(n²) performance bottlenecks that can be exploited by an attacker to conduct a denial-of-service (DoS) attack against applications rendering untrusted SVG documents. The vulnerability exists within <code>cairosvg/path.py</code> in the path-data tokenizer and the marker handling logic. The tokenizer consumes path strings using a loop that repeatedly re-slices the remaining string, leading to quadratic time complexity. Simultaneously, the marker rendering function utilizes <code>list.pop(0)</code> to drain vertices, which is an O(n) operation in Python, also resulting in O(n²) complexity.</p>
<p>An attacker can trigger this vulnerability by submitting a specially crafted SVG document with a high density of path segments. Testing demonstrates that a document under 1 MiB can consume approximately 18 seconds of CPU time. This makes any web service that utilizes CairoSVG to process user-supplied SVG files, such as those generating thumbnails, avatars, or PDF exports, highly susceptible to resource exhaustion attacks.</p>
<h2 id="impact">Impact</h2>
<p>The impact of this vulnerability is a high-availability risk for services relying on CairoSVG for image processing. By repeatedly sending these crafted SVG documents, an attacker can effectively pin CPU cores, leading to service degradation or total outage. This affects any application performing server-side rendering of user-provided content.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade to a version of CairoSVG that includes the fix for CVE-2026-107378.</li>
<li>Implement input validation on the server side to limit the number of segments allowed in a single <code>&lt;path&gt;</code> element before processing.</li>
<li>Enforce strict timeouts on image rendering jobs to mitigate the impact of CPU-intensive operations on the application server.</li>
</ol>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category></item></channel></rss>