CVE-2026-31899
HighAdvisory
Published 13 Mar 2026In the index since 6 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.005
- 41st percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 7
- of 17,781 indexed, latest versions
- Container images
- 6
- deployed by those charts
- Fix available
- 1 of 1
- affected package
CairoSVG vulnerable to Exponential DoS via recursive <use> element amplification
Carried by container images the latest versions of 7 of 17,781 indexed charts deploy, on 6 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| cairosvgpypi | 2.0.3, 2.5.2, 2.7.1, 2.8.2 | 2.9.0 | 6 |
- OSV records
- GHSA-f38f-5xpm-9r7c
- Also known as
- PYSEC-2026-2122
Charts affected
7 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| taigarc-helm-charts | 0.1.0 | 1 of 7See more | 7,255 |
| taigafermosit | 0.0.11 | 1 of 7See more | 8,496 |
| helm-taigamvitale1989-helm-taigaVerified publisher | 0.2.5 | 1 of 2See more | 5,104 |
| taigaunxwaresVerified publisher | 2026.3.8 | 1 of 6See more | 9,148 |
| esphomealexmorbo-esphomeVerified publisher | 1.0.0 | 1 of 1See more | 6,324 |
| esphomehelm-chart-roeiVerified publisher | 2025.3.0 | 1 of 1See more | 6,008 |
| esphomeretsamedocVerified publisher | 2026.2.5 | 1 of 1See more | 7,431 |
Container images carrying it
6 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| taigaio/ | 4beed8f62c9f | cairosvg | 2.9.0 | 2 |
| esphome/ | 9ab8cc88b28c | cairosvg | 2.9.0 | 1 |
| esphome/ | b2c6322700ac | cairosvg | 2.9.0 | 1 |
| esphome/ | def8b6e4f517 | cairosvg | 2.9.0 | 1 |
| mvitale1989/ | 1504ccda06df | cairosvg | 2.9.0 | 1 |
| taigaio/ | 9f97323cc150 | cairosvg | 2.9.0 | 1 |