Description
WeasyPrint helps web developers to create PDF documents. Prior to 70.0, server-side applications that configure a restrictive url_fetcher and pass attacker-influenced values to HTML.write_pdf() can have the restriction bypassed through the xmp_metadata or stylesheets options. In weasyprint/pdf/init.py, xmp_metadata calls select_source() without the document url_fetcher, allowing an accessible local file to be read and embedded verbatim in the output PDF. In weasyprint/document.py, stylesheets constructs CSS() without the document url_fetcher, allowing local or internal resource loading and propagating the permissive fetcher through nested CSS imports and url() references. The stylesheets channel applies fetched resources but does not by itself disclose stylesheet comments verbatim. This issue is fixed in version 70.0.
Published: 2026-09-14
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local file read and SSRF
Action: Patch
AI Analysis

Impact

The WeasyPrint PDF library includes a restrictive URL fetcher configuration that should limit network or file system access during PDF generation. However, prior to version 70.0, server‑side applications that set a restrictive url_fetcher and supply attacker‑controlled HTML.write_pdf() input can bypass those restrictions. In the XMP metadata handler, select_source() is called without the document’s url_fetcher, allowing the library to read any accessible local file and embed it verbatim in the output PDF. In the stylesheets processor, CSS() is constructed without the document url_fetcher, permitting local or internal resource loading and propagating a permissive fetcher through nested CSS imports and url() references. While the stylesheets channel applies fetched resources, it does not disclose comments verbatim. These behaviors result in a privacy breach, enabling a local file read and server‑side request forgery (SSRF) attack, classified under CWE‑918 and CWE‑1220. The flaw is resolved in WeasyPrint 70.0.

Affected Systems

The issue affects the WeasyPrint library from any version preceding 70.0, as distributed by Kozea. Applications that embed WeasyPrint (for example, Django or Flask projects using the HTML.write_pdf() method) are potentially vulnerable if they configure a restrictive URL fetcher and accept attacker‑controlled input for PDF generation. There are no additional vendor versions identified beyond Kozea’s WeasyPrint distribution.

Risk and Exploitability

The CVSS score of 6.2 defines the vulnerability as moderate severity. The EPSS score is now listed as less than 1 %, indicating a low but non‑zero probability of exploitation. The vulnerability is not currently in the CISA KEV catalog. Exploitation requires an attacker to influence the data fed to HTML.write_pdf(), which typically occurs through a web endpoint that generates PDFs from user‑supplied content. Once triggered, the attacker can read arbitrary local files or issue internal network requests via the library’s relaxed fetch logic. The attack vector is server‑side, posing a threat to confidentiality and integrity of server data but not directly enabling remote code execution.

Generated by OpenCVE AI on September 21, 2026 at 00:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to WeasyPrint version 70.0 or newer to apply the vendor fix.
  • Review and remove custom URL fetcher configurations that override restrictions when invoking HTML.write_pdf().
  • Sanitize or validate all data passed to HTML.write_pdf() so that it is not influenced by attacker‑controlled input, and limit PDF generation to trusted content sources.

Generated by OpenCVE AI on September 21, 2026 at 00:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-jf6q-chmf-3h3v weasyprint Has Server-Side Request Forgery (SSRF)
History

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1220
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 15 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Kozea
Kozea weasyprint
Vendors & Products Kozea
Kozea weasyprint

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description WeasyPrint helps web developers to create PDF documents. Prior to 70.0, server-side applications that configure a restrictive url_fetcher and pass attacker-influenced values to HTML.write_pdf() can have the restriction bypassed through the xmp_metadata or stylesheets options. In weasyprint/pdf/init.py, xmp_metadata calls select_source() without the document url_fetcher, allowing an accessible local file to be read and embedded verbatim in the output PDF. In weasyprint/document.py, stylesheets constructs CSS() without the document url_fetcher, allowing local or internal resource loading and propagating the permissive fetcher through nested CSS imports and url() references. The stylesheets channel applies fetched resources but does not by itself disclose stylesheet comments verbatim. This issue is fixed in version 70.0.
Title WeasyPrint restrictive URL fetcher bypass allows local file read and SSRF
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Kozea Weasyprint
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T15:19:03.064Z

Reserved: 2026-06-16T14:33:35.710Z

Link: CVE-2026-55073

cve-icon Vulnrichment

Updated: 2026-09-16T15:18:58.981Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T17:17:47.770

Modified: 2026-09-23T17:17:44.630

Link: CVE-2026-55073

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-14T16:55:12Z

Links: CVE-2026-55073 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:15:06Z

Weaknesses
  • CWE-1220

    Insufficient Granularity of Access Control

  • CWE-918

    Server-Side Request Forgery (SSRF)