<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T14:39:06.123091+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-07364</id>
    <title>bdu:2026-07364</title>
    <updated>2026-10-08T14:39:06.129839+00:00</updated>
    <content>bdu:2026-07364</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-07364"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-standardebooks-cve-2026-31899</id>
    <title>BREW-standardebooks-CVE-2026-31899 — CairoSVG vulnerable to Exponential DoS via recursive &lt;use&gt; element amplification</title>
    <updated>2026-10-08T14:39:06.129907+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: standardebooks</p>
<p>## Summary</p>
<p>Kozea/CairoSVG (~300K downloads/week) has exponential denial of service via recursive `&lt;use&gt;` element amplification in `cairosvg/defs.py` (line ~335). This causes CPU exhaustion from a small input.</p>
<p>## Severity</p>
<p>High — CVSS 3.1: 7.5
Vector: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H`</p>
<p>## Vulnerable Code</p>
<p>File: `cairosvg/defs.py` (line ~335), function `use()`</p>
<p>The `use()` function recursively processes `&lt;use&gt;` elements without any depth or count limits. With 5 levels of nesting and 10 references each, a 1,411-byte SVG triggers 10^5 = 100,000 render calls.</p>
<p>## Impact</p>
<p>- 1,411-byte SVG payload pins CPU at 100% indefinitely
- Memory stays flat at ~43MB — no OOM kill, process never terminates
- Any service accepting SVG input (thumbnailing, PDF generation, avatar rendering) is DoS-able
- Amplification factor: O(10^N) rendering calls from O(N) input</p>
<p>## Proof of Concept</p>
<p>Save as `poc.svg` and run `timeout 10 cairosvg poc.svg -o test.png`:</p>
<p>```xml
&lt;?xml version="1.0"?&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink"&gt;
  &lt;defs&gt;
    &lt;g id="a"&gt;&lt;rect width="1" height="1"/&gt;&lt;/g&gt;
    &lt;g id="b"&gt;&lt;use xlink:href="#a"/&gt;&lt;use xlink:href="#a"/&gt;&lt;use xlink:href="#a"/&gt;&lt;use xlink:href="#a"/&gt;&lt;use xlink:href="#a"/&gt;&lt;use xlink:href="#a"/&gt;&lt;use xlink:href="#a"/&gt;&lt;use xlink:href="#a"/&gt;&lt;use xlink:href="#a"/&gt;&lt;use xlink:href="#a"/&gt;&lt;/g&gt;
    &lt;g id="c"&gt;&lt;use xlink:href="#b"/&gt;&lt;use xlink:href="#b"/&gt;&lt;use xlink:href="#b"/&gt;&lt;use xlink:href="#b"/&gt;&lt;use xlink:href="#b"/&gt;&lt;use…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-standardebooks-cve-2026-31899"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-276081</id>
    <title>EUVD-2026-276081</title>
    <updated>2026-10-08T14:39:06.130004+00:00</updated>
    <content>EUVD-2026-276081</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-276081"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-31899</id>
    <title>fkie_cve-2026-31899</title>
    <updated>2026-10-08T14:39:06.130021+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to Kozea/CairoSVG has exponential denial of service via recursive &lt;use&gt; element amplification in cairosvg/defs.py. This causes CPU exhaustion from a small input.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-31899"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-f38f-5xpm-9r7c</id>
    <title>GHSA-f38f-5xpm-9r7c — CairoSVG vulnerable to Exponential DoS via recursive &lt;use&gt; element amplification</title>
    <updated>2026-10-08T14:39:06.130044+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: CairoSVG</p>
<p>## Summary</p>
<p>Kozea/CairoSVG (~300K downloads/week) has exponential denial of service via recursive `&lt;use&gt;` element amplification in `cairosvg/defs.py` (line ~335). This causes CPU exhaustion from a small input.</p>
<p>## Severity</p>
<p>High — CVSS 3.1: 7.5
Vector: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H`</p>
<p>## Vulnerable Code</p>
<p>File: `cairosvg/defs.py` (line ~335), function `use()`</p>
<p>The `use()` function recursively processes `&lt;use&gt;` elements without any depth or count limits. With 5 levels of nesting and 10 references each, a 1,411-byte SVG triggers 10^5 = 100,000 render calls.</p>
<p>## Impact</p>
<p>- 1,411-byte SVG payload pins CPU at 100% indefinitely
- Memory stays flat at ~43MB — no OOM kill, process never terminates
- Any service accepting SVG input (thumbnailing, PDF generation, avatar rendering) is DoS-able
- Amplification factor: O(10^N) rendering calls from O(N) input</p>
<p>## Proof of Concept</p>
<p>Save as `poc.svg` and run `timeout 10 cairosvg poc.svg -o test.png`:</p>
<p>```xml
&lt;?xml version="1.0"?&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink"&gt;
  &lt;defs&gt;
    &lt;g id="a"&gt;&lt;rect width="1" height="1"/&gt;&lt;/g&gt;
    &lt;g id="b"&gt;&lt;use xlink:href="#a"/&gt;&lt;use xlink:href="#a"/&gt;&lt;use xlink:href="#a"/&gt;&lt;use xlink:href="#a"/&gt;&lt;use xlink:href="#a"/&gt;&lt;use xlink:href="#a"/&gt;&lt;use xlink:href="#a"/&gt;&lt;use xlink:href="#a"/&gt;&lt;use xlink:href="#a"/&gt;&lt;use xlink:href="#a"/&gt;&lt;/g&gt;
    &lt;g id="c"&gt;&lt;use xlink:href="#b"/&gt;&lt;use xlink:href="#b"/&gt;&lt;use xlink:href="#b"/&gt;&lt;use xlink:href="#b"/&gt;&lt;use xlink:href="#b"/&gt;&lt;use…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-f38f-5xpm-9r7c"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10379-1</id>
    <title>openSUSE-SU-2026:10379-1 — python311-CairoSVG-2.9.0-1.1 on GA media</title>
    <updated>2026-10-08T14:39:06.130096+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python311-CairoSVG-2.9.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10379-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2122</id>
    <title>PYSEC-2026-2122</title>
    <updated>2026-10-08T14:39:06.130114+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: cairosvg</p>
<p>CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to Kozea/CairoSVG has exponential denial of service via recursive &lt;use&gt; element amplification in cairosvg/defs.py. This causes CPU exhaustion from a small input.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2122"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22024-1</id>
    <title>SUSE-SU-2026:22024-1 — Security update for python-CairoSVG</title>
    <updated>2026-10-08T14:39:06.130132+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-CairoSVG</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22024-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-31899</id>
    <title>UBUNTU-CVE-2026-31899</title>
    <updated>2026-10-08T14:39:06.130147+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: cairosvg, Ubuntu:18.04:LTS: cairosvg, Ubuntu:20.04:LTS: cairosvg, Ubuntu:22.04:LTS: cairosvg, Ubuntu:24.04:LTS: cairosvg, Ubuntu:25.10: cairosvg, Ubuntu:26.04:LTS: cairosvg</p>
<p>CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to Kozea/CairoSVG has exponential denial of service via recursive &lt;use&gt; element amplification in cairosvg/defs.py. This causes CPU exhaustion from a small input.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-31899"/>
  </entry>
</feed>
