---
id: CVE-2021-21236
aliases:
  - GHSA-hq37-853p-g5cf
  - PYSEC-2021-5
title: Regular Expression Denial of Service in CairoSVG
summary: Regular Expression Denial of Service in CairoSVG
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
vendor: cairosvg
product: cairosvg
ecosystem: pip
affected:
  - cairosvg < 2.5.1
patched:
  - cairosvg 2.5.1
published: '2021-01-06'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:49:14.069813467Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-hq37-853p-g5cf'
references:
  - url: 'https://github.com/Kozea/CairoSVG/security/advisories/GHSA-hq37-853p-g5cf'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2021-21236'
  - url: >-
      https://github.com/Kozea/CairoSVG/commit/cfc9175e590531d90384aa88845052de53d94bf3
  - url: 'https://github.com/Kozea/CairoSVG'
  - url: 'https://github.com/Kozea/CairoSVG/releases/tag/2.5.1'
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/cairosvg/PYSEC-2021-5.yaml
  - url: 'https://pypi.org/project/CairoSVG'
tags:
  - osv
  - pip
epss: 0.01466
epssPercentile: 0.72599
ingestedAt: '2026-09-12T03:13:01.701Z'
---

## Overview

# Doyensec Vulnerability Advisory 

* Regular Expression Denial of Service (REDoS) in cairosvg
* Affected Product: CairoSVG v2.0.0+
* Vendor: https://github.com/Kozea
* Severity: Medium
* Vulnerability Class: Denial of Service
* Author(s): Ben Caller ([Doyensec](https://doyensec.com))

## Summary

When processing SVG files, the python package CairoSVG uses two regular expressions which are vulnerable to Regular Expression Denial of Service (REDoS).
If an attacker provides a malicious SVG, it can make cairosvg get stuck processing the file for a very long time.

## Technical description

The vulnerable regular expressions are

https://github.com/Kozea/CairoSVG/blob/9c4a982b9a021280ad90e89707eacc1d114e4ac4/cairosvg/colors.py#L190-L191

The section between 'rgb(' and the final ')' contains multiple overlapping groups.

Since all three infinitely repeating groups accept spaces, a long string of spaces causes catastrophic backtracking when it is not followed by a closing parenthesis.

The complexity is cubic, so doubling the length of the malicious string of spaces makes processing take 8 times as long.

## Reproduction steps

Create a malicious SVG of the form:

    <svg width="1" height="1"><rect fill="rgb(                     ;"/></svg>

with the following code:

    '<svg width="1" height="1"><rect fill="rgb(' + (' ' * 3456) + ';"/></svg>'

Note that there is no closing parenthesis before the semi-colon.

Run cairosvg e.g.:

    cairosvg cairo-redos.svg -o x.png

and notice that it hangs at 100% CPU. Increasing the number of spaces increases the processing time with cubic complexity.

## Remediation

Fix the regexes to avoid overlapping parts. Perhaps remove the [ \n\r\t]* groups from the regex, and use .strip() on the returned capture group.

## Disclosure timeline

- 2020-12-30: Vulnerability disclosed via email to CourtBouillon

## Affected packages

- `cairosvg < 2.5.1`

## Remediation

Upgrade to a patched release:

- `cairosvg 2.5.1`
