When processing SVG files, the python package CairoSVG uses two regular
expressions which are vulnerable to Regular Expression Denial of Service
(REDoS). If an attacker provides a malicious SVG, it can make cairosvg
get stuck processing the file for a very long time (CVE-2021-21236).
- https://bugs.mageia.org/show_bug.cgi?id=28122
- https://github.com/advisories/GHSA-hq37-853p-g5cf
- https://www.cve.org/CVERecord?id=CVE-2021-21236
- 7/core/python-cairosvg-2.2.1-1.1.mga7
Get the latest Linux and open source security news straight to your inbox.