๐Ÿ” CVE Alert

CVE-2025-68616

HIGH 7.5

WeasyPrint Vulnerable to Server-Side Request Forgery (SSRF) Protection Bypass via HTTP Redirect

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

WeasyPrint helps web developers to create PDF documents. Prior to version 68.0, a server-side request forgery (SSRF) protection bypass exists in WeasyPrint's `default_url_fetcher`. The vulnerability allows attackers to access internal network resources (such as `localhost` services or cloud metadata endpoints) even when a developer has implemented a custom `url_fetcher` to block such access. This occurs because the underlying `urllib` library follows HTTP redirects automatically without re-validating the new destination against the developer's security policy. Version 68.0 contains a patch for the issue.

CWE CWE-601 CWE-918
Vendor kozea
Product weasyprint
Published Jan 19, 2026
Last Updated Jun 30, 2026
Stay Ahead of the Next One

Get instant alerts for kozea weasyprint

Be the first to know when new high vulnerabilities affecting kozea weasyprint are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

Kozea / WeasyPrint
< 68.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Kozea/WeasyPrint/security/advisories/GHSA-983w-rhvv-gwmv github.com: https://github.com/Kozea/WeasyPrint/commit/b6a14f0f3f4ce9c0c75c1a2d73cb1c5d43f0e565 access.redhat.com: https://access.redhat.com/security/cve/CVE-2025-68616 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2430858 security.access.redhat.com: https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-68616.json