Impact
`fulgur` is a library that converts untrusted HTML and CSS into PDF, often running on a server that receives content from many users. In versions before 0.19.0, when a body‐level element had a CSS‐resolved height that vastly exceeded the physical page height, the renderer sliced the element into one fragment per page with no upper bound. The slice loop could therefore iterate an unbounded number of times, consuming excessive CPU and memory until the process failed or became unresponsive, leading to a denial of service. The vulnerability derives from unbounded loop iteration and lack of bounds checking, as reflected in CWE‑400 and CWE‑835.
Affected Systems
The vulnerability affects the open‑source crate `fulgur` provided by fulgur-rs. All releases prior to version 0.19.0 are impacted. The fix was introduced in 0.19.0, which caps the slice loop with a `MAX_PAGES` limit and sanitizes non‑finite layout heights, preventing the loop from running indefinitely.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. The EPSS score of less than 1% suggests a low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. It is likely exploitable by an attacker who can supply arbitrary HTML/CSS to the server, such as through a web form or API that uses fulgur to generate PDFs. Once triggered, the server may exhaust resources or crash, interrupting service for all tenants. The lack of a bound on the slicing loop makes the attack condition relatively easy to meet given any overly large `height` or `vh` value on a body‑level element.
OpenCVE Enrichment
Github GHSA