Kozea Weasyprint vulnerabilities
2 known vulnerabilities affecting kozea/weasyprint.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2
Vulnerabilities
Page 1 of 1
CVE-2025-68616HIGHCVSS 7.5fixed in 68.02026-01-19
CVE-2025-68616 [HIGH] CWE-601 CVE-2025-68616: WeasyPrint helps web developers to create PDF documents. Prior to version 68.0, a server-side reques
WeasyPrint helps web developers to create PDF documents. Prior to version 68.0, a server-side request forgery (SSRF) protection bypass exists in WeasyPrint's `default_url_fetcher`. The vulnerability allows attackers to access internal network resources (such as `localhost` services or cloud metadata endpoints) even when a developer has implemented a c
cvelistv5ghsanvdosv
CVE-2024-28184HIGHCVSS 7.4≥ 61.0, < 61.2v>= 61.0, <= 61.12024-03-09
CVE-2024-28184 [HIGH] CWE-829 CVE-2024-28184: WeasyPrint helps web developers to create PDF documents. Since version 61.0, there's a vulnerability
WeasyPrint helps web developers to create PDF documents. Since version 61.0, there's a vulnerability which allows attaching content of arbitrary files and URLs to a generated PDF document, even if `url_fetcher` is configured to prevent access to files and URLs. This vulnerability has been patched in version 61.2.
cvelistv5ghsanvdosv