Description
`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In versions prior to 0.19.0, a body-direct child whose CSS-resolved height greatly exceeds the page height was sliced into one fragment per page with no upper bound. This is fixed in 0.19.0. A `MAX_PAGES` cap bounds the slice loop — halting it even
for a `+inf` height — and non-finite layout heights are sanitized so they can no longer drive the loop. As a workaround, validate or constrain untrusted CSS (in particular `height` / `vh` on body-level elements) before passing HTML to fulgur.
Published: 2026-09-17
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

This vulnerability arises when using fulgur to convert untrusted HTML and CSS to PDF. The issue is that an attacker can supply a body element with a CSS‑resolved height that far exceeds the page height, causing fulgur to slice the content into a fragment for each page without an upper bound. The result is an unbounded loop that consumes CPU and memory, ultimately exhausting system resources and leading to a denial‑of‑service condition. The flaw is identified as uncontrolled resource consumption (CWE‑400) and an infinite loop (CWE‑835).

Affected Systems

The problem affects the fulgur‑rs fulgur project, versions older than 0.19.0. All installations that rely on these earlier releases to convert untrusted web content on a multi‑tenant server are vulnerable. Affected builds include any release prior to 0.19.0.

Risk and Exploitability

The CVSS score of 7.5 assigns a high severity rating. The EPSS score of less than 1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA's KEV catalog. However, because the converter is typically exposed as a server that processes data supplied by external parties, an attacker can remotely send malicious HTML/CSS to trigger the crash. The exploit would perform a resource‑intensive loop that can be mitigated by the MAX_PAGES cap introduced in 0.19.0 or by sanitizing non‑finite layout heights.

Generated by OpenCVE AI on September 19, 2026 at 02:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade fulgur to version 0.19.0 or later
  • Verify that the MAX_PAGES cap is enabled in the configuration
  • Validate or constrain untrusted CSS height before passing HTML to fulgur

Generated by OpenCVE AI on September 19, 2026 at 02:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-j5cx-ph8g-95v3 Fulgur: Unbounded page slicing from attacker-controlled CSS height causes denial of service
History

Mon, 21 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Fulgur-rs
Fulgur-rs fulgur
Vendors & Products Fulgur-rs
Fulgur-rs fulgur

Thu, 17 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description `fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In versions prior to 0.19.0, a body-direct child whose CSS-resolved height greatly exceeds the page height was sliced into one fragment per page with no upper bound. This is fixed in 0.19.0. A `MAX_PAGES` cap bounds the slice loop — halting it even for a `+inf` height — and non-finite layout heights are sanitized so they can no longer drive the loop. As a workaround, validate or constrain untrusted CSS (in particular `height` / `vh` on body-level elements) before passing HTML to fulgur.
Title Fulgur: Unbounded page slicing from attacker-controlled CSS height causes denial of service
Weaknesses CWE-400
CWE-835
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Fulgur-rs Fulgur
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T21:16:02.110Z

Reserved: 2026-07-30T16:19:08.082Z

Link: CVE-2026-68523

cve-icon Vulnrichment

Updated: 2026-09-21T21:15:57.056Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T21:17:19.127

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-68523

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T02:30:17Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-835

    Loop with Unreachable Exit Condition ('Infinite Loop')