Skip navigation

Skip to main content

  • Home
  • Your apps
  • Your integrations
Engineering Blog
OverviewSubscribe
Discover more
UI/UXBackendMachine LearningInfrastructureSecurityEngineering PracticesData Platform
About Canva⁠(opens in a new tab or window)
Category

Security


Endpoint vulnerability management at scale

How we do endpoint vulnerability management at Canva.

  • SG
Santiago GutiérrezMay 7, 2024
Read more
Security

Trust but test: Vendor security testing at Canva

How we validate vendor security at Canva by going beyond compliance.

Kane Narraway, CJ FairheadMar 10, 2024
Security

Fonts are still a Helvetica of a Problem

CVEs in three strange places and the unique problem of safely processing and handling fonts.

Angus Cornall, Peter KydasMar 6, 2024
Security

When URL parsers disagree (CVE-2023-38633)

Discovery and walkthrough of CVE-2023-38633 in librsvg, when two URL parser implementations (Rust and Glib) disagree on file scheme parsing leading to path traversal.

Zac SimsSep 5, 2023
Security

Discovering Headroll (CVE-2023–0704) in Chromium

Discovery of Headless Chromium security vulnerability, how it works, and mitigations that should be applied to similar configurations

Zac Sims, Rhys ElsmoreApr 5, 2023

Privacy policyTerms
© 2025 All Rights Reserved. Canva®