Kozea

Weasyprint

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.69%
  • Veröffentlicht 06.10.2026 19:18:13
  • Zuletzt bearbeitet 06.10.2026 20:17:26

WeasyPrint helps web developers to create PDF documents. Prior to 70.0, the image-loading path in weasyprint/images.py passes fetched image bytes from HTML img URLs, CSS image values, SVG image references, and data URIs to Pillow's generic image disp...

  • EPSS 0.19%
  • Veröffentlicht 14.09.2026 16:55:12
  • Zuletzt bearbeitet 23.09.2026 17:17:44

WeasyPrint helps web developers to create PDF documents. Prior to 70.0, server-side applications that configure a restrictive url_fetcher and pass attacker-influenced values to HTML.write_pdf() can have the restriction bypassed through the xmp_metada...

  • EPSS 0.27%
  • Veröffentlicht 18.08.2026 18:17:49
  • Zuletzt bearbeitet 18.09.2026 20:09:01

WeasyPrint helps web developers to create PDF documents. Prior to 69.0, WeasyPrint embeds unescaped HTML presentational-hint attribute values into CSS in weasyprint/css/__init__.py when presentational_hints=True. The background attribute is inserted ...

Exploit
  • EPSS 0.65%
  • Veröffentlicht 19.01.2026 15:20:23
  • Zuletzt bearbeitet 15.07.2026 02:17:50

WeasyPrint helps web developers to create PDF documents. Prior to version 68.0, a server-side request forgery (SSRF) protection bypass exists in WeasyPrint's `default_url_fetcher`. The vulnerability allows attackers to access internal network resourc...

  • EPSS 0.62%
  • Veröffentlicht 09.03.2024 01:15:07
  • Zuletzt bearbeitet 02.12.2025 21:57:58

WeasyPrint helps web developers to create PDF documents. Since version 61.0, there's a vulnerability which allows attaching content of arbitrary files and URLs to a generated PDF document, even if `url_fetcher` is configured to prevent access to file...