MEDIUM 6.2 GitHub

CVE-2026-55073

weasyprint Has Server-Side Request Forgery (SSRF)

## Summary `url_fetcher` is WeasyPrint's documented mechanism for restricting resource loading - applications use it to block `file://`, internal hosts, etc. when rendering untrusted input. Two `write_pdf()` channels ignore the document's `url_fetcher` and build a fresh default `URLFetcher()` instead. A restrictive fetcher set on `HTML()` is silently bypassed for: - **`xmp_metadata=[url]`** - the URL is fetched and the bytes are embedded verbatim in the output PDF. This is an **arbitrary loca

Affected Products

References

Published: 2026-09-09 · Source: GitHub · Feed updated: 2026-09-11
This medium severity vulnerability with a CVSS score of 6.2 was published on 2026-09-09 via GitHub. Affected: pip/weasyprint < 70.0.
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.