Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107378— CairoSVG: Quadratic-time DoS parsing a crafted SVG <path>

Quick assessment

Affected
Kozea CairoSVG
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

CairoSVG 是一个基于 Cairo(一个二维图形库)的 SVG 转换器。在版本 2.9.1 之前,渲染包含大量路径线段的、由攻击者控制的 SVG 文件时,会导致 cairosvg/path.py 中出现二次方级别的 CPU 消耗。路径标记化器(path tokenizer)会反复切片并重新扫描剩余的路径数据,而 draw_markers 函数通过 node.vertices.pop(0) 方式逐个移除节点顶点,导致重复的线性时间开销。svg2png、svg2pdf 和 svg2ps 等 API 在正常渲染过程

CVSS 8.7 · High

Possible ATT&CK Techniques 1 AI

T1496 · Resource Hijacking

Affected Version Matrix 1

VendorProduct Version RangeStatus
Kozea CairoSVG < 2.9.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107378

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
CairoSVG: Quadratic-time DoS parsing a crafted SVG <path>
Source: CVE Program / CVE List V5
Vulnerability Description
CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to 2.9.1, rendering an attacker-controlled SVG with a path containing many segments can cause quadratic CPU consumption in cairosvg/path.py. The path tokenizer repeatedly slices and rescans the remaining path data, while draw_markers drains node.vertices with node.vertices.pop(0), causing repeated linear-time work. The svg2png, svg2pdf, and svg2ps APIs reach these operations during ordinary rendering, allowing a sub-megabyte SVG to consume substantial CPU and deny service to a rendering application. This issue is fixed in version 2.9.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
算法复杂性
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Kozea CairoSVG < 2.9.1 -

II. Public POCs for CVE-2026-107378

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107378

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-107378 (1)

Other References for CVE-2026-107378 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-107378

No comments yet


Leave a comment