{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-20T16:18:40.852","vulnerabilities":[{"cve":{"id":"CVE-2021-21236","sourceIdentifier":"security-advisories@github.com","published":"2021-01-06T17:15:23.733","lastModified":"2024-11-21T05:47:50.170","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"CairoSVG is a Python (pypi) package. CairoSVG is an SVG converter based on Cairo. In CairoSVG before version 2.5.1, there is a regular expression denial of service (REDoS) vulnerability. When processing SVG files, the python package CairoSVG uses two regular expressions which are vulnerable to Regular Expression Denial of Service (REDoS). If an attacker provides a malicious SVG, it can make cairosvg get stuck processing the file for a very long time. This is fixed in version 2.5.1. See Referenced GitHub advisory for more information."},{"lang":"es","value":"CairoSVG es un paquete de Python (pypi).&#xa0;CairoSVG es un conversor de SVG basado en Cairo.&#xa0;En CairoSVG versiones anteriores a 2.5.1, se presenta de denegación de servicio de expresión regular (REDoS).&#xa0;Cuando se procesan archivos SVG, el paquete de python CairoSVG utiliza dos expresiones regulares que son vulnerables a una Denegación de Servicio de Expresiones Regulares (REDoS).&#xa0;Si un atacante proporciona un SVG malicioso, puede hacer que cairosvg se atasque al procesar el archivo durante mucho tiempo.&#xa0;Esto es corregido en la versión 2.5.1.&#xa0;Consulte el aviso Referenced GitHub para obtener más información"}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","baseScore":5.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.1,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:N/A:P","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:courtbouillon:cairosvg:*:*:*:*:*:*:*:*","versionEndExcluding":"2.5.1","matchCriteriaId":"6D10055D-3299-4F39-B4E2-A52D95ABB225"}]}]}],"references":[{"url":"https://github.com/Kozea/CairoSVG/commit/cfc9175e590531d90384aa88845052de53d94bf3","source":"security-advisories@github.com","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/Kozea/CairoSVG/releases/tag/2.5.1","source":"security-advisories@github.com","tags":["Release Notes","Third Party Advisory"]},{"url":"https://github.com/Kozea/CairoSVG/security/advisories/GHSA-hq37-853p-g5cf","source":"security-advisories@github.com","tags":["Exploit","Third Party Advisory"]},{"url":"https://pypi.org/project/CairoSVG/","source":"security-advisories@github.com","tags":["Product","Third Party Advisory"]},{"url":"https://github.com/Kozea/CairoSVG/commit/cfc9175e590531d90384aa88845052de53d94bf3","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/Kozea/CairoSVG/releases/tag/2.5.1","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Third Party Advisory"]},{"url":"https://github.com/Kozea/CairoSVG/security/advisories/GHSA-hq37-853p-g5cf","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]},{"url":"https://pypi.org/project/CairoSVG/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Product","Third Party Advisory"]}]}}]}