Vulnerability PYSEC-2026-2122

High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
6 months ago
March 13, 2026 at 07:54 PM UTC
No summary available
0.1 - 2.8.2
0.1 - 2.8.2

Details

CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to Kozea/CairoSVG has exponential denial of service via recursive element amplification in cairosvg/defs.py. This causes CPU exhaustion from a small input.

Impacted packages

Timeline

Published
6 months ago
March 13, 2026 at 07:54 PM UTC
Fixed (2.9.0)
6 months ago
March 13, 2026 at 03:42 PM UTC
Last Modified
2 months ago
July 13, 2026 at 07:15 AM UTC