Vulnerability PYSEC-2021-5
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
5 years ago
January 06, 2021 at 05:15 PM UTC
No summary available
0.1 - 2.5.0
0.1 - 2.5.0
Details
CairoSVG is a Python (pypi) package. CairoSVG is an SVG converter based on Cairo. In CairoSVG before version 2.5.1, there is a regular expression denial of service (REDoS) vulnerability. When processing SVG files, the python package CairoSVG uses two regular expressions which are vulnerable to Regular Expression Denial of Service (REDoS). If an attacker provides a malicious SVG, it can make cairosvg get stuck processing the file for a very long time. This is fixed in version 2.5.1. See Referenced GitHub advisory for more information.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
4 hours ago
CairoSVG: Quadratic-time DoS parsing a crafted SVG <path>
0.1 - 2.9.0 GHSA-c3jg-qh8m-j3h2
0.1 - 2.9.0 GHSA-c3jg-qh8m-j3h2
High Risk
6 months ago
No summary available
0.1 - 2.8.2 PYSEC-2026-2122
0.1 - 2.8.2 PYSEC-2026-2122
High Risk
6 months ago
CairoSVG vulnerable to Exponential DoS via recursive <use> element amplification
0.1 - 2.8.2 GHSA-f38f-5xpm-9r7c
0.1 - 2.8.2 GHSA-f38f-5xpm-9r7c
Critical
3 years ago
CairoSVG improperly processes SVG files loaded from external resources
0.1 - 2.6.0 GHSA-rwmf-w63j-p7gv
0.1 - 2.6.0 GHSA-rwmf-w63j-p7gv
Unknown
3 years ago
No summary available
0.1 - 2.6.0 PYSEC-2023-9
0.1 - 2.6.0 PYSEC-2023-9
Impacted packages
Timeline
Published
5 years ago
January 06, 2021 at 05:15 PM UTC
Fixed (2.5.1)
5 years ago
January 06, 2021 at 02:54 PM UTC
Last Modified
2 years ago
November 08, 2023 at 04:04 AM UTC