---
id: CVE-2026-107378
title: 'CairoSVG is an SVG converter based on Cairo, a 2D graphics library'
summary: >-
  CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to
  2.9.1, rendering an attacker-controlled SVG with a path containing many
  segments can cause quadratic CPU consumption in cairosvg/path.py. The path
  tokenizer rep…
severity: high
cwe:
  - CWE-407
vendor: cairosvg
product: cairosvg
affected:
  - cairosvg <= 2.9.0
patched:
  - cairosvg 2.9.1
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:33:42.423'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107378'
references:
  - url: >-
      https://github.com/Kozea/CairoSVG/commit/9d63f049f9988d0ddda3eb94564ac3a50a286523
    label: security-advisories@github.com
  - url: >-
      https://github.com/Kozea/CairoSVG/commit/a4d585eb374724b79676e9cceaa9e9a1a4358565
    label: security-advisories@github.com
  - url: 'https://github.com/Kozea/CairoSVG/releases/tag/2.9.1'
    label: security-advisories@github.com
  - url: 'https://github.com/Kozea/CairoSVG/security/advisories/GHSA-c3jg-qh8m-j3h2'
    label: security-advisories@github.com
  - url: 'https://github.com/Kozea/CairoSVG/security/advisories/GHSA-c3jg-qh8m-j3h2'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107378'
  - url: 'https://github.com/advisories/GHSA-c3jg-qh8m-j3h2'
tags:
  - nvd
  - ghsa
  - pip
aliases:
  - GHSA-c3jg-qh8m-j3h2
ecosystem: pip
ingestedAt: '2026-10-08T18:58:11.313Z'
---

## Overview

CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to 2.9.1, rendering an attacker-controlled SVG with a path containing many segments can cause quadratic CPU consumption in cairosvg/path.py. The path tokenizer repeatedly slices and rescans the remaining path data, while draw_markers drains node.vertices with node.vertices.pop(0), causing repeated linear-time work. The svg2png, svg2pdf, and svg2ps APIs reach these operations during ordinary rendering, allowing a sub-megabyte SVG to consume substantial CPU and deny service to a rendering application. This issue is fixed in version 2.9.1.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-107378)

Affected packages:

- `cairosvg <= 2.9.0`

Patched in:

- `cairosvg 2.9.1`

Source: https://github.com/advisories/GHSA-c3jg-qh8m-j3h2
