<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T02:55:03.067210+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-384743</id>
    <title>EUVD-2026-384743</title>
    <updated>2026-10-09T02:55:03.069700+00:00</updated>
    <content>EUVD-2026-384743</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-384743"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-107378</id>
    <title>fkie_cve-2026-107378</title>
    <updated>2026-10-09T02:55:03.069745+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to 2.9.1, rendering an attacker-controlled SVG with a path containing many segments can cause quadratic CPU consumption in cairosvg/path.py. The path tokenizer repeatedly slices and rescans the remaining path data, while draw_markers drains node.vertices with node.vertices.pop(0), causing repeated linear-time work. The svg2png, svg2pdf, and svg2ps APIs reach these operations during ordinary rendering, allowing a sub-megabyte SVG to consume substantial CPU and deny service to a rendering application. This issue is fixed in version 2.9.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-107378"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-c3jg-qh8m-j3h2</id>
    <title>GHSA-c3jg-qh8m-j3h2 — CairoSVG: Quadratic-time DoS parsing a crafted SVG &lt;path&gt;</title>
    <updated>2026-10-09T02:55:03.069783+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: cairosvg</p>
<p>## Summary</p>
<p>Rendering an untrusted SVG whose `&lt;path d="..."&gt;` contains many segments is O(n²) CPU. A single `&lt;path&gt;` under 1 MiB burns tens of seconds. Two independent O(n²) sites in `cairosvg/path.py`:</p>
<p>1. **Tokenizer** — the path-data parser consumes the `d` string with a `while string:` loop that repeatedly slices/re-scans the *remaining* string (each step is O(len remaining)), giving O(n²) over the whole attribute.
2. **draw_markers** — marker handling drains `node.vertices` with `while node.vertices: ... node.vertices.pop(0)`; `list.pop(0)` is O(n), so draining n vertices is O(n²).</p>
<p>Both are hit on a normal render path (`svg2png`/`svg2pdf`), attacker controls only the SVG document.</p>
<p>## PoC (installed cairosvg 2.9.0)</p>
<p>```python
import cairosvg
d = "M0 0 " + "L1 1 " * 100000
svg = f'&lt;svg xmlns="http://www.w3.org/2000/svg" width="10" height="10"&gt;&lt;path d="{d}"/&gt;&lt;/svg&gt;'
cairosvg.svg2png(bytestring=svg.encode())   # ~4.4 s for a 488 KB doc
```</p>
<p>| path segments | SVG size | time |
|---|---|---|
| 50,000 | 244 KB | 1.14 s |
| 100,000 | 488 KB | 4.36 s |
| 200,000 | ~960 KB | ~18 s |</p>
<p>Doubling segments ≈ 4× time ⇒ quadratic. Sub-MiB input ⇒ ~18 s CPU; any service rendering user-supplied SVG (thumbnails, avatars, PDF export) is a DoS target.</p>
<p>## Reachability</p>
<p>Public API `svg2png` / `svg2pdf` / `svg2ps` on an untrusted SVG string.</p>
<p>## Suggested fix</p>
<p>Tokenize with a single forward scan / index (or `re.finditer`) instead of re-slicing the remainder; drain `vertices` with an index or…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-c3jg-qh8m-j3h2"/>
  </entry>
</feed>
