Description
`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In versions prior to 0.19.0, a body-direct child whose CSS-resolved height greatly exceeds the page height was sliced into one fragment per page with no upper bound. This is fixed in version 0.19.0. A `MAX_PAGES` cap bounds the slice loop — halting it even for a `+inf` height — and non-finite layout heights are sanitized so they can no longer drive the loop. As a workaround, validate or constrain untrusted CSS (in particular `height` / `vh` on body-level elements) before passing HTML to fulgur.
Published: 2026-09-17
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Immediately
AI Analysis

Impact

`fulgur` is a library that converts untrusted HTML and CSS into PDF, often running on a server that receives content from many users. In versions before 0.19.0, when a body‐level element had a CSS‐resolved height that vastly exceeded the physical page height, the renderer sliced the element into one fragment per page with no upper bound. The slice loop could therefore iterate an unbounded number of times, consuming excessive CPU and memory until the process failed or became unresponsive, leading to a denial of service. The vulnerability derives from unbounded loop iteration and lack of bounds checking, as reflected in CWE‑400 and CWE‑835.

Affected Systems

The vulnerability affects the open‑source crate `fulgur` provided by fulgur-rs. All releases prior to version 0.19.0 are impacted. The fix was introduced in 0.19.0, which caps the slice loop with a `MAX_PAGES` limit and sanitizes non‑finite layout heights, preventing the loop from running indefinitely.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity. The EPSS score of less than 1% suggests a low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. It is likely exploitable by an attacker who can supply arbitrary HTML/CSS to the server, such as through a web form or API that uses fulgur to generate PDFs. Once triggered, the server may exhaust resources or crash, interrupting service for all tenants. The lack of a bound on the slicing loop makes the attack condition relatively easy to meet given any overly large `height` or `vh` value on a body‑level element.

Generated by OpenCVE AI on September 19, 2026 at 00:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update fulgur to version 0.19.0 or newer to apply the vendor fix that caps the page slicing loop.
  • Before passing client input to fulgur, sanitize and constrain untrusted CSS, especially the `height` and `vh` properties of body‑level elements, to prevent excessively large values.
  • Configure or respect the `MAX_PAGES` setting in fulgur configuration to limit the total number of pages processed during rendering.

Generated by OpenCVE AI on September 19, 2026 at 00:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-4rf6-qx84-q9fv Fulgur: Non-painting replaced elements amplify to thousands of blank PDF pages (denial of service)
History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Fulgur-rs
Fulgur-rs fulgur
Vendors & Products Fulgur-rs
Fulgur-rs fulgur

Fri, 18 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description `fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In versions prior to 0.19.0, a body-direct child whose CSS-resolved height greatly exceeds the page height was sliced into one fragment per page with no upper bound. This is fixed in version 0.19.0. A `MAX_PAGES` cap bounds the slice loop — halting it even for a `+inf` height — and non-finite layout heights are sanitized so they can no longer drive the loop. As a workaround, validate or constrain untrusted CSS (in particular `height` / `vh` on body-level elements) before passing HTML to fulgur.
Title Fulgur: Unbounded page slicing from attacker-controlled CSS height causes denial of service
Weaknesses CWE-400
CWE-835
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Fulgur-rs Fulgur
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T20:23:12.488Z

Reserved: 2026-07-30T19:56:44.100Z

Link: CVE-2026-68537

cve-icon Vulnrichment

Updated: 2026-09-17T20:23:07.332Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T21:17:19.870

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-68537

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T00:15:13Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-835

    Loop with Unreachable Exit Condition ('Infinite Loop')