SB20260424174 - Resource exhaustion in CairoSVG
Published: April 24, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource exhaustion (CVE-ID: CVE-2026-31899)
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the use() function in cairosvg/defs.py when processing crafted SVG input with recursively nested
A small input can trigger exponential rendering amplification and sustained CPU exhaustion without significant memory growth.
Remediation
Install update from vendor's website.