{"id":"CVE-2025-68616","summary":"WeasyPrint Vulnerable to Server-Side Request Forgery (SSRF) Protection Bypass via HTTP Redirect","details":"WeasyPrint helps web developers to create PDF documents. Prior to version 68.0, a server-side request forgery (SSRF) protection bypass exists in WeasyPrint's `default_url_fetcher`. The vulnerability allows attackers to access internal network resources (such as `localhost` services or cloud metadata endpoints) even when a developer has implemented a custom `url_fetcher` to block such access. This occurs because the underlying `urllib` library follows HTTP redirects automatically without re-validating the new destination against the developer's security policy. Version 68.0 contains a patch for the issue.","aliases":["GHSA-983w-rhvv-gwmv","PYSEC-2026-2034"],"modified":"2026-08-12T03:51:08.148840659Z","published":"2026-01-19T15:20:23.702Z","related":["openSUSE-SU-2026:10079-1","openSUSE-SU-2026:20069-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68616.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-601","CWE-918"]},"references":[{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-68616.json"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2025-68616"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68616.json"},{"type":"ADVISORY","url":"https://github.com/Kozea/WeasyPrint/security/advisories/GHSA-983w-rhvv-gwmv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-68616"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2430858"},{"type":"FIX","url":"https://github.com/Kozea/WeasyPrint/commit/b6a14f0f3f4ce9c0c75c1a2d73cb1c5d43f0e565"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/kozea/weasyprint","events":[{"introduced":"0"},{"fixed":"e9352befffdb1754462b160c38a7e8903a4e28d7"},{"fixed":"b6a14f0f3f4ce9c0c75c1a2d73cb1c5d43f0e565"}],"database_specific":{"cpe":"cpe:2.3:a:kozea:weasyprint:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"68.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v67.0","v66.0","v65.0","v64.1","v64.0","v63.1","v63.0","v62.1","v62.0","v61.1","v61.0","v60.1","v60.0","v59.0","v58.1","v59.0b1","v58.0","v58.0b1","v57.1","v57.0","v57.0b1","v56.0b1","v55.0b1","v54.0","v54.0b1","v53.0","v53.0b2","v53.0b1","v51","v50","v49","v48","v47","v46","v45","v44","v43","v43rc2","v43rc1","v0.42","v0.41","v0.40","v0.39","v0.38","v0.37","v0.36","v0.35","v0.34","v0.33","v0.32","v0.31","v0.30","v0.29","v0.28","v0.27","v0.26","v0.25","v0.24","v0.20.1","v0.20","v0.19.1","v0.19","v0.18","v0.17.1","v0.17","v0.16","v0.15","v0.14","v0.13","v0.12","v0.11","v0.10","v0.9","v0.8","v0.7","v0.6","v0.5","v0.2","v0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-68616.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}