Impact
CairoSVG has a quadratic‑time denial‑of‑service flaw that triggers when parsing an SVG <path> element containing many segments. The path tokenizer repeatedly slices and rescans the entire path string, and the marker drawing logic repeatedly removes items from the front of a list, leading to excessive CPU consumption. The result is that processing a sub‑megabyte SVG can exhaust system resources and halt rendering applications. This flaw is classified as CWE‑407 (Excessive Computation).
Affected Systems
The affected product is Kozea's CairoSVG, versions earlier than 2.9.1. Applications that use CairoSVG’s svg2png, svg2pdf, or svg2ps APIs are directly vulnerable. Any process that renders attacker‑controlled SVG files can be impacted. The vulnerability is fixed in release 2.9.1 and later.
Risk and Exploitability
The CVSS v3.1 score of 8.7 indicates high severity. No EPSS score is publicly available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves providing a crafted SVG to a rendering application, a task that an attacker can perform through file uploads, email attachments, or web requests. Because the flaw manifests during normal rendering, the exploit is straightforward for anyone who can feed SVG data to the vulnerable library, making it a high‑risk denial‑of‑service attack.
OpenCVE Enrichment
Github GHSA