← Back to browse · API

CVE-2023-27586

Severity
CRITICAL
CVSS
9.9
EPSS
0.00722
Risk score
39.85
CISA KEV
No
PoC
No
Published
2023-03-20
Modified
2025-02-25
First seen
2026-08-07
Aliases
EUVD-2023-0051, GHSA-RWMF-W63J-P7GV, PYSEC-2023-9
Products
Kozea:CairoSVG < 2.7.0
Sources
euvd EUVD-2023-0051

Description

CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to version 2.7.0, Cairo can send requests to external hosts when processing SVG files. A malicious actor could send a specially crafted SVG file that allows them to perform a server-side request forgery or denial of service. Version 2.7.0 disables CairoSVG's ability to access other files online by default.

References