Resource exhaustion in CairoSVG - CVE-2026-31899

 

Resource exhaustion in CairoSVG - CVE-2026-31899

Published: April 24, 2026


Vulnerability identifier: #VU127613
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-31899
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in the use() function in cairosvg/defs.py when processing crafted SVG input with recursively nested elements. A remote attacker can send a specially crafted SVG file or document to cause a denial of service.

A small input can trigger exponential rendering amplification and sustained CPU exhaustion without significant memory growth.


Affected software

CairoSVG
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Fedora
Python 3 Module
openSUSE Leap
python-cairosvg
python311-CairoSVG

How to mitigate CVE-2026-31899

Install security update from vendor's website.

CairoSVG - update to 2.9.0
python-cairosvg - addressed in versions 2.7.0-2.el9, 2.9.0-1.el10_1, 2.9.0-1.el10_2, 2.9.0-1.el10_3, 2.9.0-1.fc42, 2.9.0-1.fc43, 2.9.0-1.fc44
python311-CairoSVG - update to 2.7.1-150400.9.6.1

External References

Related Security Bulletins