๐Ÿ” CVE Alert

CVE-2026-106443

HIGH 8.8

WeasyPrint: EPS images reach the Ghostscript interpreter resulting in RCE

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

WeasyPrint helps web developers to create PDF documents. Prior to 70.0, the image-loading path in weasyprint/images.py passes fetched image bytes from HTML img URLs, CSS image values, SVG image references, and data URIs to Pillow's generic image dispatcher without excluding EPS or PostScript formats. On hosts with Ghostscript installed, Pillow EpsImagePlugin invokes the interpreter for attacker-controlled PostScript, which can produce interpreter-permitted effects and can lead to remote code execution when the installed Ghostscript version has a usable sandbox bypass. Hosts without Ghostscript do not reach this rasterization path. This issue is fixed in version 70.0.

CWE CWE-20
Vendor kozea
Product weasyprint
Published Oct 6, 2026
Last Updated Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for kozea weasyprint

Be the first to know when new high vulnerabilities affecting kozea weasyprint are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Kozea / WeasyPrint
< 70.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Kozea/WeasyPrint/security/advisories/GHSA-r543-q48m-4c9j github.com: https://github.com/Kozea/WeasyPrint/commit/39cd37ce1610bd890388e26591c569db1cbab542 github.com: https://github.com/Kozea/WeasyPrint/releases/tag/v70.0