GHSA-f38f-5xpm-9r7c
HIGHCVE-2026-31899Kozea/CairoSVG (~300K downloads/week) has exponential denial of service via recursive <use> element amplification in cairosvg/defs.py (line ~335). This causes CPU exhaustion from a small input.
- Affected
- <= 2.8.2
- Fixed in
- 2.9.0
- Weakness
- CWE-400
- Published
- 2026-03-13
- Source
- github