#1150245 weasyprint: CVE-2026-106443

Package:
src:weasyprint
Source:
src:weasyprint
Submitter:
Salvatore Bonaccorso
Date:
2026-10-08 06:27:03 UTC
Severity:
normal
Tags:
#1150245#5
Date:
2026-10-07 14:49:53 UTC
From:
To:
Hi,

The following vulnerability was published for weasyprint.

CVE-2026-106443[0]:
| WeasyPrint helps web developers to create PDF documents. Prior to
| 70.0, the image-loading path in weasyprint/images.py passes fetched
| image bytes from HTML img URLs, CSS image values, SVG image
| references, and data URIs to Pillow's generic image dispatcher
| without excluding EPS or PostScript formats. On hosts with
| Ghostscript installed, Pillow EpsImagePlugin invokes the interpreter
| for attacker-controlled PostScript, which can produce interpreter-
| permitted effects and can lead to remote code execution when the
| installed Ghostscript version has a usable sandbox bypass. Hosts
| without Ghostscript do not reach this rasterization path. This issue
| is fixed in version 70.0.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-106443
https://www.cve.org/CVERecord?id=CVE-2026-106443
[1] https://github.com/Kozea/WeasyPrint/security/advisories/GHSA-r543-q48m-4c9j
[2] https://github.com/Kozea/WeasyPrint/commit/39cd37ce1610bd890388e26591c569db1cbab542

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1150245#10
Date:
2026-10-08 06:24:11 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
weasyprint, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1150245@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Alexandre Detiste <tchet@debian.org> (supplier of updated weasyprint package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Thu, 08 Oct 2026 07:42:49 +0200
Source: weasyprint
Architecture: source
Version: 70.0-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Python Team <team+python@tracker.debian.org>
Changed-By: Alexandre Detiste <tchet@debian.org>
Closes: 1148178 1150245
Changes:
 weasyprint (70.0-1) unstable; urgency=medium
 .
   * Team upload
   * New upstream version 70.0
     * CVE-2026-55073 input validation, secret disclosure (Closes: #1148178)
     * CVE-2026-106443 Ghostscript sandbox bypass (Closes: #1150245)
   * Build-depends on python3-flit instead of the whole 'flit' toolbox
   * Add debian/salsa-ci.yml
   * Drop 'Rules-Requires-Root: no': it is now the default
   * Rewrite d/watch in v5 format
Checksums-Sha1:
 f23e4969efbbb0a3075816b6e129237840e4d610 2316 weasyprint_70.0-1.dsc
 5ab628bf1bb4222061758a6b89a66caed8eefedd 1565482 weasyprint_70.0.orig.tar.gz
 5aad5b25f5848ed6325de9a7cb34d8a945a2d2cf 5460 weasyprint_70.0-1.debian.tar.xz
 f74d11ee37e1f8999705d8ed7ad8d3581b8018df 12080 weasyprint_70.0-1_source.buildinfo
Checksums-Sha256:
 84f9b9250a6402f94513002567260a27ad2337b6a622671c313032a4933db5a4 2316 weasyprint_70.0-1.dsc
 c263abf0e86c747b12af678b67f85f4abbfb97d18a20503031e7ba94e4b8cf8c 1565482 weasyprint_70.0.orig.tar.gz
 6a0edd51d78c85308f4e9bca891cecd127a4244123adc7d0d71587c1c2c1d85f 5460 weasyprint_70.0-1.debian.tar.xz
 83dff72e66002ce37ba76aa5c4256ac9e47eb6baca62cac7e796f83a30939b8e 12080 weasyprint_70.0-1_source.buildinfo
Files:
 79fd8d450340cf1e3fa6f7ff1a30e2fb 2316 text optional weasyprint_70.0-1.dsc
 bc6f55c033f3013f418f672991f4d754 1565482 text optional weasyprint_70.0.orig.tar.gz
 791fa320b7aec5778a15e96feba6d4a0 5460 text optional weasyprint_70.0-1.debian.tar.xz
 d77c7f13d6f28466ad932f6bba419fae 12080 text optional weasyprint_70.0-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQJFBAEBCgAvFiEEj23hBDd/OxHnQXSHMfMURUShdBoFAmrHLh4RHHRjaGV0QGRl
Ymlhbi5vcmcACgkQMfMURUShdBpnfQ//a+2LC3moDOwEA+8cHE4NjipQi1T7pD0e
w6oA2ruaRGFOVtQDFXZl4dcmLLjjuco6yEw3kDQq+NQIAEYz58dWlMPf7T1e8UqY
lLE8lom/QCYCknUsDMJzAKUS0h7CR5Nxsw5JJTBqJieiAvA7qCclADnZUGf/xGSK
XsL93J/5cQ/4lwhSmn6YIZOpY3Oa9j2OCMharFT2ymr75tHm9K0zD7tAvFozuTZq
cFMinNClgBlocuvyZyqCjqNnbDIt02UwB+c7xw6S00aZnn4f1On8wZaYlNMTGHr8
ezqqAQD+nHYijBZoNfxlREWC/MT9ZNNWP54/bDknG4LDSUi/d0KKY29Lpi6NdT9k
2+fHun+g8fqdynorT/0rpNkh5dKkwVeEjA8M/x2U+t2nnmYwgJVfTiOfrI/NSak4
9n+aDXgSfc3S4L7XJT7eQssG+imL5AsyMAyLBvAqvqiYImb6S4YmVBBJ6bEo22+d
7L0KVM880LG951VKDgKtM7Tkd1cb2VDTf4+vYjRAdxl4vY3/59s7t6ZRgRLpZmR8
3k42oOYrgSx3gn5Ks44Cek+XzU+s8yotbHx1eflbq/+TZCYPCtK01Y8DfB2QkPz4
1cGbFEuMB2ucAJwWozm2mX14xYUdx0BvVMj+j+vbtzwPOcI09YSVUqFjYPlG0MfY
PX17qIbSs1k=
=Ejnn
-----END PGP SIGNATURE-----