#1148178 weasyprint: CVE-2026-55073

Package:
src:weasyprint
Source:
src:weasyprint
Submitter:
Salvatore Bonaccorso
Date:
2026-09-17 20:35:03 UTC
Severity:
normal
Tags:
#1148178#5
Date:
2026-09-17 20:33:01 UTC
From:
To:
Hi,

The following vulnerability was published for weasyprint.

CVE-2026-55073[0]:
| WeasyPrint helps web developers to create PDF documents. Prior to
| 70.0, server-side applications that configure a restrictive
| url_fetcher and pass attacker-influenced values to HTML.write_pdf()
| can have the restriction bypassed through the xmp_metadata or
| stylesheets options. In weasyprint/pdf/init.py, xmp_metadata calls
| select_source() without the document url_fetcher, allowing an
| accessible local file to be read and embedded verbatim in the output
| PDF. In weasyprint/document.py, stylesheets constructs CSS() without
| the document url_fetcher, allowing local or internal resource
| loading and propagating the permissive fetcher through nested CSS
| imports and url() references. The stylesheets channel applies
| fetched resources but does not by itself disclose stylesheet
| comments verbatim. This issue is fixed in version 70.0.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-55073
https://www.cve.org/CVERecord?id=CVE-2026-55073
[1] https://github.com/Kozea/WeasyPrint/security/advisories/GHSA-jf6q-chmf-3h3v
[2] https://github.com/Kozea/WeasyPrint/commit/289e278439b017cd9263b4cd4727026987f86443

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore