PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-106443 Kozea CVE debrief

WeasyPrint, a popular Python library for rendering web pages, is vulnerable to remote code execution (RCE) when processing EPS images. The vulnerability arises from WeasyPrint's image pipeline, which passes fetched image bytes directly to Pillow's generic format dispatcher without restricting the input format. When Ghostscript is installed on the host, Pillow's EpsImagePlugin invokes it to rasterize attacker-controlled EPS/PS input, potentially leading to RCE. This issue was discovered during a pentest funded by the NLNnet foundation, conducted by Stefan Vink from Radically Open Security. The vulnerability affects systems using WeasyPrint, especially those with Ghostscript

Vendor
Kozea
Product
weasyprint
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for systems using WeasyPrint, especially those with Ghostscript installed, should assess potential exposure and impact. This includes operators, platform administrators, vulnerability management teams, and security teams who need to prioritize verifying exposure, assessing potential impact, and implementing compensating controls to restrict image input formats.

Why it matters

Defenders should prioritize verifying exposure and assessing potential impact due to remote code execution potential and unrestricted image input formats.

  • Remote code execution potential when Ghostscript is installed
  • Unrestricted image input formats allow attacker-controlled PostScript
  • Exposure in systems using WeasyPrint with Ghostscript

Technical summary

WeasyPrint passes fetched image bytes directly to Pillow's generic format dispatcher without restricting the input format. When Ghostscript is installed on the host, Pillow's EpsImagePlugin invokes it to rasterize attacker-controlled EPS/PS input, potentially leading to remote code execution. The image pipeline reads an external response and hands the raw bytes to Pillow's format-agnostic Image.open, with no allowlist of safe raster formats. This issue allows any content that can supply an image to WeasyPrint (an <img> URL, CSS image value, SVG image reference, or data URI) to drive untrusted PostScript into an external interpreter.

Defensive priority

Defenders should prioritize verifying exposure and assessing potential impact, focusing on systems using WeasyPrint with Ghostscript installed.

Recommended defensive actions

  • Verify WeasyPrint versions and configurations to ensure they are not vulnerable
  • Assess potential impact on systems using WeasyPrint with Ghostscript installed
  • Implement compensating controls to restrict image input formats
  • Monitor for potential exploitation attempts
  • Review vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The issue was found during a pentest funded by the NLNnet foundation, conducted by Stefan Vink from Radically Open Security. WeasyPrint passes fetched image bytes directly to Pillow's generic format dispatcher without restricting the input format, which can lead to remote code execution when Ghostscript is installed on the host.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-106443 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-106443

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-106443 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106443

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • WeasyPrint: EPS images reach the Ghostscript interpreter resulting in RCE

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/PyPI/GHSA-r543-q48m-4c9j.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Kozea/WeasyPrint/security/advisories/GHSA-r543-q48m-4c9j

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Kozea/WeasyPrint/commit/39cd37ce1610bd890388e26591c569db1cbab542

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Kozea/WeasyPrint

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Kozea/WeasyPrint/releases/tag/v70.0

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.