CVE-2026-55073 WeasyPrint PDF Creation Restriction Bypass. A restriction bypass vulnerability exists in WeasyPrint versions prior to 70.0, allowing server-side applications with restrictive url_fetcher configurations to potentially read local files and embed them in generated PDFs through the xmp_metadata or stylesheets options. Developers and administrators should assess exposure, verify configurations, [truncated]
CVE-2026-49452 debrief: WeasyPrint embeds unescaped HTML presentational-hint attribute values into CSS, allowing CSS injection and potential server-side requests through injected url() values. This issue is fixed in version 69.0. Affected product deployments should be identified in managed environments, and owners should assess exposure and consider upgrades or mitigations. The vulnerability allows untrus [truncated]
CVE-2025-68616 is a high-severity vulnerability in WeasyPrint, a Python library for generating PDF documents. The vulnerability allows attackers to bypass SSRF protection and access internal network resources. This occurs because the underlying urllib library follows HTTP redirects automatically without re-validating the new destination against the developer's security policy. WeasyPrint versions prior to [truncated]