weasyprint vulnerabilities
CVEs whose affected-version data names the weasyprint package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-55073Medium· 6.2PoCWeasyPrint helps web developers to create PDF documents
WeasyPrint helps web developers to create PDF documents. Prior to 70.0, server-side applications that configure a restrictive url_fetcher and pass attacker-influenced values to HTML.write_pdf() can have the restriction bypassed through t…
CVE-2026-49452Medium· 6.5WeasyPrint helps web developers to create PDF documents
WeasyPrint helps web developers to create PDF documents. Prior to 69.0, WeasyPrint embeds unescaped HTML presentational-hint attribute values into CSS in weasyprint/css/__init__.py when presentational_hints=True. The background attribute…
CVE-2025-68616High· 7.5PoCWeasyPrint helps web developers to create PDF documents
WeasyPrint helps web developers to create PDF documents. Prior to version 68.0, a server-side request forgery (SSRF) protection bypass exists in WeasyPrint's `default_url_fetcher`. The vulnerability allows attackers to access internal ne…
CVE-2024-28184High· 7.4WeasyPrint allows the attachment of arbitrary files and URLs to a PDF
WeasyPrint allows the attachment of arbitrary files and URLs to a PDF