{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/cairosvg/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:cairosvg:cairosvg:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-107378"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["CairoSVG (\u003c= 2.9.0)"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["CairoSVG"],"content_html":"\u003cp\u003eCairoSVG versions 2.9.0 and earlier contain two independent O(n²) performance bottlenecks that can be exploited by an attacker to conduct a denial-of-service (DoS) attack against applications rendering untrusted SVG documents. The vulnerability exists within \u003ccode\u003ecairosvg/path.py\u003c/code\u003e in the path-data tokenizer and the marker handling logic. The tokenizer consumes path strings using a loop that repeatedly re-slices the remaining string, leading to quadratic time complexity. Simultaneously, the marker rendering function utilizes \u003ccode\u003elist.pop(0)\u003c/code\u003e to drain vertices, which is an O(n) operation in Python, also resulting in O(n²) complexity.\u003c/p\u003e\n\u003cp\u003eAn attacker can trigger this vulnerability by submitting a specially crafted SVG document with a high density of path segments. Testing demonstrates that a document under 1 MiB can consume approximately 18 seconds of CPU time. This makes any web service that utilizes CairoSVG to process user-supplied SVG files, such as those generating thumbnails, avatars, or PDF exports, highly susceptible to resource exhaustion attacks.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe impact of this vulnerability is a high-availability risk for services relying on CairoSVG for image processing. By repeatedly sending these crafted SVG documents, an attacker can effectively pin CPU cores, leading to service degradation or total outage. This affects any application performing server-side rendering of user-provided content.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade to a version of CairoSVG that includes the fix for CVE-2026-107378.\u003c/li\u003e\n\u003cli\u003eImplement input validation on the server side to limit the number of segments allowed in a single \u003ccode\u003e\u0026lt;path\u0026gt;\u003c/code\u003e element before processing.\u003c/li\u003e\n\u003cli\u003eEnforce strict timeouts on image rendering jobs to mitigate the impact of CPU-intensive operations on the application server.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-08T19:44:04Z","date_published":"2026-10-08T19:44:04Z","id":"https://feed.craftedsignal.io/briefs/2026-10-cairosvg-dos/","summary":"CairoSVG versions 2.9.0 and earlier are vulnerable to a CPU-exhaustion denial-of-service attack due to O(n²) complexity in SVG path-data parsing and marker rendering.","title":"CairoSVG Quadratic-Time Denial of Service","url":"https://feed.craftedsignal.io/briefs/2026-10-cairosvg-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - CairoSVG","version":"https://jsonfeed.org/version/1.1"}