GHSA-c3jg-qh8m-j3h2: Pip/cairosvg vulnerability

Published Oct 8, 2026
·
Updated

Summary

Rendering an untrusted SVG whose <path d="..."> contains many segments is O(n²) CPU. A single <path> under 1 MiB burns tens of seconds. Two independent O(n²) sites in cairosvg/path.py:

1. Tokenizer — the path-data parser consumes the d string with a while string: loop that repeatedly slices/re-scans the remaining string (each step is O(len remaining)), giving O(n²) over the whole attribute. 2. drawmarkers — marker handling drains node.vertices with while node.vertices: ... node.vertices.pop(0); list.pop(0) is O(n), so draining n vertices is O(n²).

Both are hit on a normal render path (svg2png/svg2pdf), attacker controls only the SVG document.

PoC (installed cairosvg 2.9.0)

python import cairosvg d = "M0 0 " + "L1 1 " 100000 svg = f'<svg xmlns="http://www.w3.org/2000/svg" width="10" height="10"><path d="{d}"/></svg>' cairosvg.svg2png(bytestring=svg.encode()) # ~4.4 s for a 488 KB doc

| path segments | SVG size | time | |---|---|---| | 50,000 | 244 KB | 1.14 s | | 100,000 | 488 KB | 4.36 s | | 200,000 | ~960 KB | ~18 s |

Doubling segments ≈ 4× time ⇒ quadratic. Sub-MiB input ⇒ ~18 s CPU; any service rendering user-supplied SVG (thumbnails, avatars, PDF export) is a DoS target.

Reachability

Public API svg2png / svg2pdf / svg2ps on an untrusted SVG string.

Suggested fix

Tokenize with a single forward scan / index (or re.finditer) instead of re-slicing the remainder; drain vertices with an index or collections.deque.popleft instead of list.pop(0). Optionally cap path-segment count.

Affected Software

1 affected componentFixes available
pip/cairosvg<=2.9.0
2.9.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pip/cairosvg to a version that resolves this vulnerability.

    Fixed in 2.9.1
  2. Compensating control

    In cairosvg/path.py, tokenize path data with a single forward scan or re.finditer instead of repeatedly slicing and rescanning the remaining string; in draw_markers, drain node.vertices with an index or collections.deque.popleft instead of list.pop(0).

  3. Compensating control

    Optionally cap the number of path segments accepted when rendering untrusted SVG documents.

Event History

Oct 8, 2026
Advisory Published
via GitHub·07:41 PM
Data Sourced
via GitHub·07:41 PM
DescriptionWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are realistically exposed?

Services or applications that render user-supplied SVG documents with CairoSVG through normal svg2png or svg2pdf processing are exposed. An attacker only needs control of the SVG document.

2

Does exploitation require a large upload or special rendering option?

No. The demonstrated input uses a single path attribute with many segments; a document below 1 MiB can consume tens of seconds of CPU. The issue is reached on the normal render path.

3

What is the practical impact of repeated requests?

The work grows quadratically with the number of path segments, so increasing segment count can sharply increase CPU time. Repeated rendering of crafted SVGs can therefore exhaust rendering capacity or cause request delays.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203