<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 02:54:38 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-384743</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-384743</link>
      <description>EUVD-2026-384743</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-384743</guid>
    </item>
    <item>
      <title>fkie_cve-2026-107378</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-107378</link>
      <description>&lt;p&gt;CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to 2.9.1, rendering an attacker-controlled SVG with a path containing many segments can cause quadratic CPU consumption in cairosvg/path.py. The path tokenizer repeatedly slices and rescans the remaining path data, while draw_markers drains node.vertices with node.vertices.pop(0), causing repeated linear-time work. The svg2png, svg2pdf, and svg2ps APIs reach these operations during ordinary rendering, allowing a sub-megabyte SVG to consume substantial CPU and deny service to a rendering application. This issue is fixed in version 2.9.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to 2.9.1, rendering an attacker-controlled SVG with a path containing many segments can cause quadratic CPU consumption in cairosvg/path.py. The path tokenizer repeatedly slices and rescans the remaining path data, while draw_markers drains node.vertices with node.vertices.pop(0), causing repeated linear-time work. The svg2png, svg2pdf, and svg2ps APIs reach these operations during ordinary rendering, allowing a sub-megabyte SVG to consume substantial CPU and deny service to a rendering application. This issue is fixed in version 2.9.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-107378</guid>
    </item>
    <item>
      <title>GHSA-c3jg-qh8m-j3h2 — CairoSVG: Quadratic-time DoS parsing a crafted SVG &lt;path&gt;</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-c3jg-qh8m-j3h2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: cairosvg&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Rendering an untrusted SVG whose `&amp;lt;path d=&amp;#34;...&amp;#34;&amp;gt;` contains many segments is O(n²) CPU. A single `&amp;lt;path&amp;gt;` under 1 MiB burns tens of seconds. Two independent O(n²) sites in `cairosvg/path.py`:&lt;/p&gt;
&lt;p&gt;1. **Tokenizer** — the path-data parser consumes the `d` string with a `while string:` loop that repeatedly slices/re-scans the *remaining* string (each step is O(len remaining)), giving O(n²) over the whole attribute.
2. **draw_markers** — marker handling drains `node.vertices` with `while node.vertices: ... node.vertices.pop(0)`; `list.pop(0)` is O(n), so draining n vertices is O(n²).&lt;/p&gt;
&lt;p&gt;Both are hit on a normal render path (`svg2png`/`svg2pdf`), attacker controls only the SVG document.&lt;/p&gt;
&lt;p&gt;## PoC (installed cairosvg 2.9.0)&lt;/p&gt;
&lt;p&gt;```python
import cairosvg
d = &amp;#34;M0 0 &amp;#34; + &amp;#34;L1 1 &amp;#34; * 100000
svg = f&amp;#39;&amp;lt;svg xmlns=&amp;#34;http://www.w3.org/2000/svg&amp;#34; width=&amp;#34;10&amp;#34; height=&amp;#34;10&amp;#34;&amp;gt;&amp;lt;path d=&amp;#34;{d}&amp;#34;/&amp;gt;&amp;lt;/svg&amp;gt;&amp;#39;
cairosvg.svg2png(bytestring=svg.encode())   # ~4.4 s for a 488 KB doc
```&lt;/p&gt;
&lt;p&gt;| path segments | SVG size | time |
|---|---|---|
| 50,000 | 244 KB | 1.14 s |
| 100,000 | 488 KB | 4.36 s |
| 200,000 | ~960 KB | ~18 s |&lt;/p&gt;
&lt;p&gt;Doubling segments ≈ 4× time ⇒ quadratic. Sub-MiB input ⇒ ~18 s CPU; any service rendering user-supplied SVG (thumbnails, avatars, PDF export) is a DoS target.&lt;/p&gt;
&lt;p&gt;## Reachability&lt;/p&gt;
&lt;p&gt;Public API `svg2png` / `svg2pdf` / `svg2ps` on an untrusted SVG string.&lt;/p&gt;
&lt;p&gt;## Suggested fix&lt;/p&gt;
&lt;p&gt;Tokenize with a single forward scan / index (or `re.finditer`) instead of re-slicing the remainder; drain `vertices` with an index or…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: cairosvg&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Rendering an untrusted SVG whose `&amp;lt;path d=&amp;#34;...&amp;#34;&amp;gt;` contains many segments is O(n²) CPU. A single `&amp;lt;path&amp;gt;` under 1 MiB burns tens of seconds. Two independent O(n²) sites in `cairosvg/path.py`:&lt;/p&gt;
&lt;p&gt;1. **Tokenizer** — the path-data parser consumes the `d` string with a `while string:` loop that repeatedly slices/re-scans the *remaining* string (each step is O(len remaining)), giving O(n²) over the whole attribute.
2. **draw_markers** — marker handling drains `node.vertices` with `while node.vertices: ... node.vertices.pop(0)`; `list.pop(0)` is O(n), so draining n vertices is O(n²).&lt;/p&gt;
&lt;p&gt;Both are hit on a normal render path (`svg2png`/`svg2pdf`), attacker controls only the SVG document.&lt;/p&gt;
&lt;p&gt;## PoC (installed cairosvg 2.9.0)&lt;/p&gt;
&lt;p&gt;```python
import cairosvg
d = &amp;#34;M0 0 &amp;#34; + &amp;#34;L1 1 &amp;#34; * 100000
svg = f&amp;#39;&amp;lt;svg xmlns=&amp;#34;http://www.w3.org/2000/svg&amp;#34; width=&amp;#34;10&amp;#34; height=&amp;#34;10&amp;#34;&amp;gt;&amp;lt;path d=&amp;#34;{d}&amp;#34;/&amp;gt;&amp;lt;/svg&amp;gt;&amp;#39;
cairosvg.svg2png(bytestring=svg.encode())   # ~4.4 s for a 488 KB doc
```&lt;/p&gt;
&lt;p&gt;| path segments | SVG size | time |
|---|---|---|
| 50,000 | 244 KB | 1.14 s |
| 100,000 | 488 KB | 4.36 s |
| 200,000 | ~960 KB | ~18 s |&lt;/p&gt;
&lt;p&gt;Doubling segments ≈ 4× time ⇒ quadratic. Sub-MiB input ⇒ ~18 s CPU; any service rendering user-supplied SVG (thumbnails, avatars, PDF export) is a DoS target.&lt;/p&gt;
&lt;p&gt;## Reachability&lt;/p&gt;
&lt;p&gt;Public API `svg2png` / `svg2pdf` / `svg2ps` on an untrusted SVG string.&lt;/p&gt;
&lt;p&gt;## Suggested fix&lt;/p&gt;
&lt;p&gt;Tokenize with a single forward scan / index (or `re.finditer`) instead of re-slicing the remainder; drain `vertices` with an index or…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-c3jg-qh8m-j3h2</guid>
    </item>
  </channel>
</rss>
