CVE-2026-31899 is a high-severity exponential denial of service vulnerability affecting CairoSVG and courtbouillon cairosvg, stemming from recursive <use> element amplification that can lead to CPU exhaustion. With a CVSS score of 7.5, this vulnerability can be exploited remotely with low complexity, requiring no user interaction to trigger a system-wide denial of service. There is currently no evidence of active exploitation, nor are there any public exploits available or significant community discussion or media coverage regarding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.9.0CPE matchmatch criteria | cpe:2.3:a:courtbouillon:cairosvg:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.