Sploitus

CVE-2026-31899

2 known exploits for CVE-2026-31899

CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to Kozea/CairoSVG has exponential denial of service via recursive <use> element amplification in cairosvg/defs.py. This causes CPU exhaustion from a small input.

Affected products
Cairo, Cairosvg, Red Os
Courtbouillon Cairosvg
< 2.9.0
Fix
Available
CVSS 3.1
7.5 HIGH
EPSS
0.5% (40th percentile)
Weakness
CWE-674
NVD status
Analyzed
Published
2026-03-13
CVE-2026-31899 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2026-31899

Proof-of-concept code and exploit modules indexed by Sploitus