cairosvg vulnerabilities
CVEs whose affected-version data names the cairosvg package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-31899High· 7.5PoCCairoSVG vulnerable to Exponential DoS via recursive <use> element amplification
CairoSVG vulnerable to Exponential DoS via recursive <use> element amplification
▾ Midnightcairosvg · cairosvgEPSS 0.49%via OSV
CVE-2023-27586Critical· 9.9CairoSVG improperly processes SVG files loaded from external resources
CairoSVG improperly processes SVG files loaded from external resources
▾ Midnightcairosvg · cairosvgEPSS 0.72%via OSV
CVE-2021-21236High· 7.5Regular Expression Denial of Service in CairoSVG
Regular Expression Denial of Service in CairoSVG
▾ Twilightcairosvg · cairosvgEPSS 1.5%via OSV