Vendor
CairoSVG versions 2.9.0 and earlier are vulnerable to a CPU-exhaustion denial-of-service attack due to O(n²) complexity in SVG path-data parsing and marker rendering.