CVE-2021-21236
Regular Expression Denial of Service in CairoSVG
Description
CairoSVG is a Python (pypi) package. CairoSVG is an SVG converter based on Cairo. In CairoSVG before version 2.5.1, there is a regular expression denial of service (REDoS) vulnerability. When processing SVG files, the python package CairoSVG uses two regular expressions which are vulnerable to Regular Expression Denial of Service (REDoS). If an attacker provides a malicious SVG, it can make cairosvg get stuck processing the file for a very long time. This is fixed in version 2.5.1. See Referenced GitHub advisory for more information.
How to fix CVE-2021-21236
To remediate CVE-2021-21236, upgrade the affected package to a fixed version below.
- —upgrade to 2.5.0-1.1 or later
- —upgrade to 2.5.1 or later
- —upgrade to cfc9175e590531d90384aa88845052de53d94bf3 or later
Is CVE-2021-21236 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0, < 2.5.0-1.1
- from 0, < 2.5.1
- from 0, < cfc9175e590531d90384aa88845052de53d94bf3 | from 0, < 2.5.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P |
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |