Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39894
HistoryMar 22, 2023 - 12:44 a.m.

Server-side Request Forgery (SSRF)

2023-03-2200:44:11
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
23
server-side request forgery
denial of service
external host resources
parsing
application crash

EPSS

0.001

Percentile

38.6%

cairosvg is vulnerable to Server-side Request Forgery (SSRF) and Denial of Service (DOS). The vulnerability is due to allowing the loading of external host resources by default during parsing, allowing an attacker to parse a maliciously crafted file from an external resource, resulting in Server-side Request Forgery and possibly cause an application crash.