Vulnerability PYSEC-2026-2122
High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
6 months ago
March 13, 2026 at 07:54 PM UTC
No summary available
0.1 - 2.8.2
0.1 - 2.8.2
Details
CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to Kozea/CairoSVG has exponential denial of service via recursive element amplification in cairosvg/defs.py. This causes CPU exhaustion from a small input.
References
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
4 hours ago
CairoSVG: Quadratic-time DoS parsing a crafted SVG <path>
0.1 - 2.9.0 GHSA-c3jg-qh8m-j3h2
0.1 - 2.9.0 GHSA-c3jg-qh8m-j3h2
High Risk
6 months ago
CairoSVG vulnerable to Exponential DoS via recursive <use> element amplification
0.1 - 2.8.2 GHSA-f38f-5xpm-9r7c
0.1 - 2.8.2 GHSA-f38f-5xpm-9r7c
Critical
3 years ago
CairoSVG improperly processes SVG files loaded from external resources
0.1 - 2.6.0 GHSA-rwmf-w63j-p7gv
0.1 - 2.6.0 GHSA-rwmf-w63j-p7gv
Unknown
3 years ago
No summary available
0.1 - 2.6.0 PYSEC-2023-9
0.1 - 2.6.0 PYSEC-2023-9
Unknown
5 years ago
No summary available
0.1 - 2.5.0 PYSEC-2021-5
0.1 - 2.5.0 PYSEC-2021-5
Impacted packages
Timeline
Published
6 months ago
March 13, 2026 at 07:54 PM UTC
Fixed (2.9.0)
6 months ago
March 13, 2026 at 03:42 PM UTC
Last Modified
2 months ago
July 13, 2026 at 07:15 AM UTC