CVE-2023-27586

unknown
Published 2023-03-20 · Modified 2023-11-08
CVSS v3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L
CVSS v2
VIR risk

Description

CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to version 2.7.0, Cairo can send requests to external hosts when processing SVG files. A malicious actor could send a specially crafted SVG file that allows them to perform a server-side request forgery or denial of service. Version 2.7.0 disables CairoSVG's ability to access other files online by default.

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2023-27586

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed2.5.2-1.1
debian debianbullseyefixed2.5.0-1.1+deb11u1
debian debianforkyfixed2.5.2-1.1
debian debiansidfixed2.5.2-1.1
debian debiantrixiefixed2.5.2-1.1

Package impact

EcosystemPackageVulnerableFixed
python PyPIcairosvg<2.7.02.7.0
python PyPIcairosvg<33007d4af9195e2bfb2ff9af064c4c2d8e4b2b53||<2.7.012d31c653c0254fa9d9853f66b04ea46e7397255

References

Verify integrity in audit chain (admin only). AS-IS.