{"id":"CVE-2026-107378","title":"CairoSVG is an SVG converter based on Cairo, a 2D graphics library","summary":"CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to 2.9.1, rendering an attacker-controlled SVG with a path containing many segments can cause quadratic CPU consumption in cairosvg/path.py. The path tokenizer rep…","severity":"high","cwe":["CWE-407"],"vendor":"cairosvg","product":"cairosvg","affected":["cairosvg <= 2.9.0"],"patched":["cairosvg 2.9.1"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T21:33:42.423","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-107378","references":[{"url":"https://github.com/Kozea/CairoSVG/commit/9d63f049f9988d0ddda3eb94564ac3a50a286523","label":"security-advisories@github.com"},{"url":"https://github.com/Kozea/CairoSVG/commit/a4d585eb374724b79676e9cceaa9e9a1a4358565","label":"security-advisories@github.com"},{"url":"https://github.com/Kozea/CairoSVG/releases/tag/2.9.1","label":"security-advisories@github.com"},{"url":"https://github.com/Kozea/CairoSVG/security/advisories/GHSA-c3jg-qh8m-j3h2","label":"security-advisories@github.com"},{"url":"https://github.com/Kozea/CairoSVG/security/advisories/GHSA-c3jg-qh8m-j3h2","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107378"},{"url":"https://github.com/advisories/GHSA-c3jg-qh8m-j3h2"}],"tags":["nvd","ghsa","pip"],"aliases":["GHSA-c3jg-qh8m-j3h2"],"ecosystem":"pip","ingestedAt":"2026-10-08T18:58:11.313Z","slug":"CVE-2026-107378","body":"## Overview\n\nCairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to 2.9.1, rendering an attacker-controlled SVG with a path containing many segments can cause quadratic CPU consumption in cairosvg/path.py. The path tokenizer repeatedly slices and rescans the remaining path data, while draw_markers drains node.vertices with node.vertices.pop(0), causing repeated linear-time work. The svg2png, svg2pdf, and svg2ps APIs reach these operations during ordinary rendering, allowing a sub-megabyte SVG to consume substantial CPU and deny service to a rendering application. This issue is fixed in version 2.9.1.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-107378)\n\nAffected packages:\n\n- `cairosvg <= 2.9.0`\n\nPatched in:\n\n- `cairosvg 2.9.1`\n\nSource: https://github.com/advisories/GHSA-c3jg-qh8m-j3h2","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":218273,"id":"CVE-2026-107378","ts":1791490029487,"field":"severity","old":"none","new":"high"}]}