Impact
This vulnerability arises when using fulgur to convert untrusted HTML and CSS to PDF. The issue is that an attacker can supply a body element with a CSS‑resolved height that far exceeds the page height, causing fulgur to slice the content into a fragment for each page without an upper bound. The result is an unbounded loop that consumes CPU and memory, ultimately exhausting system resources and leading to a denial‑of‑service condition. The flaw is identified as uncontrolled resource consumption (CWE‑400) and an infinite loop (CWE‑835).
Affected Systems
The problem affects the fulgur‑rs fulgur project, versions older than 0.19.0. All installations that rely on these earlier releases to convert untrusted web content on a multi‑tenant server are vulnerable. Affected builds include any release prior to 0.19.0.
Risk and Exploitability
The CVSS score of 7.5 assigns a high severity rating. The EPSS score of less than 1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA's KEV catalog. However, because the converter is typically exposed as a server that processes data supplied by external parties, an attacker can remotely send malicious HTML/CSS to trigger the crash. The exploit would perform a resource‑intensive loop that can be mitigated by the MAX_PAGES cap introduced in 0.19.0 or by sanitizing non‑finite layout heights.
OpenCVE Enrichment
Github GHSA