Resource exhaustion in CairoSVG - CVE-2026-31899
Published: April 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the use() function in cairosvg/defs.py when processing crafted SVG input with recursively nested
A small input can trigger exponential rendering amplification and sustained CPU exhaustion without significant memory growth.
Affected software
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Fedora
Python 3 Module
openSUSE Leap
python-cairosvg
python311-CairoSVG
How to mitigate CVE-2026-31899
python-cairosvg - addressed in versions 2.7.0-2.el9, 2.9.0-1.el10_1, 2.9.0-1.el10_2, 2.9.0-1.el10_3, 2.9.0-1.fc42, 2.9.0-1.fc43, 2.9.0-1.fc44
python311-CairoSVG - update to 2.7.1-150400.9.6.1
External References
Related Security Bulletins
- Resource exhaustion in CairoSVG
- Fedora 43 update for python-cairosvg
- Fedora 42 update for python-cairosvg
- Fedora 44 update for python-cairosvg
- Fedora EPEL 10.2 update for python-cairosvg
- Fedora EPEL 10.3 update for python-cairosvg
- Fedora EPEL 9 update for python-cairosvg
- Fedora EPEL 10.1 update for python-cairosvg
- SUSE update for python-CairoSVG