pypi package report

Is cairosvg safe?

4 known vulnerabilities, worst severity HIGH.

// reach

7 direct dependencies

1 carry known advisories, worst CRITICAL

36 packages depend on it

an advisory here reaches each of them

  • ag2
  • ai-parrot
Create a free accountfor every dependency path, dependent and what to upgrade
// ai models

3 published models carry an advisory from this package

0 pin a version the advisory is confirmed against; the rest declare it without a version.

jinaai/jina-embeddings-v5-omni-nanoHIGHnot pinned
jinaai/jina-embeddings-v5-omni-smallHIGHnot pinned

3 published models

0 declared · 3 observed · 0 inferred

ModelEvidence
jinaai/jina-embeddings-v5-omni-nanoobserved
jinaai/jina-embeddings-v5-omni-smallobserved
Create a free accountto see all 1 models and per-model risk

3 published AI models are associated with this package: 0 name it in a requirements or pyproject file, 3 load it or import it directly, and 0 are inferred from the runtime stack their declared library pulls in. Only 0 state a version requirement, so this is not a count of affected models.


cvss
0.0
high

severity band, no base score published

epss
not scored

chance of exploitation in 30 days

xyz score
not scored

CyberXYZ composite out of 10

fig. 01 — GHSA-c3jg-qh8m-j3h2, the advisory selected below

// 4 advisories

GHSA-c3jg-qh8m-j3h2

HIGHCVE-2026-107378
// summary

Rendering an untrusted SVG whose contains many segments is O(n²) CPU. A single under 1 MiB burns tens of seconds. Two independent O(n²) sites in cairosvg/path.py:

  • Tokenizer — the path-data parser consumes the d string with a while string: loop that repeatedly slices/re-scans the remaining string (each step is O(len remaining)), giving O(n²) over the whole attribute.
  • drawmarkers — marker handling drains node.vertices with while node.vertices: ... node.vertices.pop(0); list.pop(0) is O(n), so draining n vertices is O(n²).

Both are hit on a normal render path (svg2png/svg2pdf), attacker controls only the SVG document.

// poc (installed cairosvg 2.9.0)
import cairosvg
d = "M0 0 " + "L1 1 " * 100000
svg = f''
cairosvg.svg2png(bytestring=svg.encode())   # ~4.4 s for a 488 KB doc

| path segments | SVG size | time | |---|---|---| | 50,000 | 244 KB | 1.14 s | | 100,000 | 488 KB | 4.36 s | | 200,000 | ~960 KB | ~18 s |

Doubling segments ≈ 4× time ⇒ quadratic. Sub-MiB input ⇒ ~18 s CPU; any service rendering user-supplied SVG (thumbnails, avatars, PDF export) is a DoS target.

// reachability

Public API svg2png / svg2pdf / svg2ps on an untrusted SVG string.

// suggested fix

Tokenize with a single forward scan / index (or re.finditer) instead of re-slicing the remainder; drain vertices with an index or collections.deque.popleft instead of list.pop(0). Optionally cap path-segment count.


Checked 2026-10-08 at 22:58 UTC. The most recent advisory here was published 2026-10-08. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.