CVE-2023-27586

CRITICAL

Courtbouillon Cairosvg < 2.7.0 - SSRF

Title source: rule
STIX 2.1

Description

CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to version 2.7.0, Cairo can send requests to external hosts when processing SVG files. A malicious actor could send a specially crafted SVG file that allows them to perform a server-side request forgery or denial of service. Version 2.7.0 disables CairoSVG's ability to access other files online by default.

Scores

CVSS v3 9.9
EPSS 0.0009
EPSS Percentile 24.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-918 CWE-20
Status published
Products (2)
courtbouillon/cairosvg < 2.7.0
pypi/CairoSVG 0 - 2.7.0PyPI
Published Mar 20, 2023
Tracked Since Feb 18, 2026