Vulnerability PYSEC-2023-9
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
3 years ago
March 20, 2023 at 04:15 PM UTC
No summary available
0.1 - 2.6.0
0.1 - 2.6.0
Details
CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to version 2.7.0, Cairo can send requests to external hosts when processing SVG files. A malicious actor could send a specially crafted SVG file that allows them to perform a server-side request forgery or denial of service. Version 2.7.0 disables CairoSVG's ability to access other files online by default.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
4 hours ago
CairoSVG: Quadratic-time DoS parsing a crafted SVG <path>
0.1 - 2.9.0 GHSA-c3jg-qh8m-j3h2
0.1 - 2.9.0 GHSA-c3jg-qh8m-j3h2
High Risk
6 months ago
No summary available
0.1 - 2.8.2 PYSEC-2026-2122
0.1 - 2.8.2 PYSEC-2026-2122
High Risk
6 months ago
CairoSVG vulnerable to Exponential DoS via recursive <use> element amplification
0.1 - 2.8.2 GHSA-f38f-5xpm-9r7c
0.1 - 2.8.2 GHSA-f38f-5xpm-9r7c
Critical
3 years ago
CairoSVG improperly processes SVG files loaded from external resources
0.1 - 2.6.0 GHSA-rwmf-w63j-p7gv
0.1 - 2.6.0 GHSA-rwmf-w63j-p7gv
Unknown
5 years ago
No summary available
0.1 - 2.5.0 PYSEC-2021-5
0.1 - 2.5.0 PYSEC-2021-5
Impacted packages
Timeline
Published
3 years ago
March 20, 2023 at 04:15 PM UTC
Fixed (2.7.0)
3 years ago
March 20, 2023 at 02:33 PM UTC
Last Modified
2 years ago
November 08, 2023 at 04:12 AM UTC