CVE-2026-31899
CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to Kozea/CairoSVG has exponential denial of service via recursive <use> element amplification in cairosvg/defs.py. This causes CPU exhaustion from a small input.
- Courtbouillon Cairosvg
- < 2.9.0
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 0.5% (40th percentile)
- Weakness
- CWE-674
- NVD status
- Analyzed
- Published
- 2026-03-13
CVE-2026-31899 at NVD
2 known exploits for CVE-2026-31899
Proof-of-concept code and exploit modules indexed by Sploitus