id: PYSEC-2026-2122 published: "2026-03-13T19:54:38.190Z" modified: "2026-07-13T05:48:09.161962Z" aliases: - CVE-2026-31899 - GHSA-f38f-5xpm-9r7c details: CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to Kozea/CairoSVG has exponential denial of service via recursive element amplification in cairosvg/defs.py. This causes CPU exhaustion from a small input. affected: - package: name: cairosvg ecosystem: PyPI purl: pkg:pypi/cairosvg ranges: - type: ECOSYSTEM events: - introduced: "0" - fixed: 2.9.0 versions: - "0.1" - 0.1.1 - 0.1.2 - "0.2" - "0.3" - 0.3.1 - "0.4" - 0.4.1 - 0.4.2 - 0.4.3 - 0.4.4 - "0.5" - "1.0" - 1.0.1 - 1.0.10 - 1.0.11 - 1.0.12 - 1.0.13 - 1.0.14 - 1.0.15 - 1.0.16 - 1.0.17 - 1.0.18 - 1.0.19 - 1.0.2 - 1.0.20 - 1.0.21 - 1.0.22 - 1.0.3 - 1.0.4 - 1.0.5 - 1.0.6 - 1.0.7 - 1.0.8 - 1.0.9 - 2.0.0 - 2.0.0rc1 - 2.0.0rc2 - 2.0.0rc3 - 2.0.0rc4 - 2.0.0rc5 - 2.0.0rc6 - 2.0.1 - 2.0.2 - 2.0.3 - 2.1.0 - 2.1.1 - 2.1.2 - 2.1.3 - 2.2.0 - 2.2.1 - 2.3.0 - 2.3.1 - 2.4.0 - 2.4.1 - 2.4.2 - 2.5.0 - 2.5.1 - 2.5.2 - 2.6.0 - 2.7.0 - 2.7.1 - 2.8.0 - 2.8.1 - 2.8.2 ecosystem_specific: {} references: - type: FIX url: https://github.com/Kozea/CairoSVG/commit/6dde8685ed3f19837767bce7a13a5491e3d0e0bf - type: EVIDENCE url: https://github.com/Kozea/CairoSVG/security/advisories/GHSA-f38f-5xpm-9r7c severity: - type: CVSS_V3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H