CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to version 2.7.0, Cairo can send requests to external hosts when processing SVG files. A malicious actor could send a specially crafted SVG file that allows them to perform a server-side request forgery or denial of service. Version 2.7.0 disables CairoSVG's ability to access other files online by default.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5382-1 | cairosvg security update |
EUVD |
EUVD-2023-0051 | CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to version 2.7.0, Cairo can send requests to external hosts when processing SVG files. A malicious actor could send a specially crafted SVG file that allows them to perform a server-side request forgery or denial of service. Version 2.7.0 disables CairoSVG's ability to access other files online by default. |
Github GHSA |
GHSA-rwmf-w63j-p7gv | CairoSVG improperly processes SVG files loaded from external resources |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 25 Feb 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-25T14:52:14.700Z
Reserved: 2023-03-04T01:03:53.634Z
Link: CVE-2023-27586
Updated: 2024-08-02T12:16:36.330Z
Status : Modified
Published: 2023-03-20T16:15:13.197
Modified: 2024-11-21T07:53:12.313
Link: CVE-2023-27586
No data.
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Github GHSA