{"id":"PYSEC-2026-2056","summary":"xhtml2pdf Denial of Service via crafted string","details":"An issue in the getcolor function in utils.py of xhtml2pdf v0.2.13 allows attackers to cause a Regular expression Denial of Service (ReDOS) via supplying a crafted string.","aliases":["CVE-2024-25885","GHSA-jj5c-hhrg-vv5h"],"modified":"2026-07-07T17:48:17.621101873Z","published":"2026-07-07T14:34:42.774289Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-25885"},{"type":"WEB","url":"https://gist.github.com/salvatore-abello/c88dd0027496774023ef36c7b576d206"},{"type":"PACKAGE","url":"https://github.com/xhtml2pdf/xhtml2pdf"},{"type":"PACKAGE","url":"https://pypi.org/project/xhtml2pdf"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-jj5c-hhrg-vv5h"}],"affected":[{"package":{"name":"xhtml2pdf","ecosystem":"PyPI","purl":"pkg:pypi/xhtml2pdf"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"0.2.16"}]}],"versions":["0.0.0","0.0.1","0.0.2","0.0.3","0.0.4","0.0.5","0.0.6","0.1a1","0.1a2","0.1a3","0.1a4","0.1b1","0.1b2","0.1b3","0.2","0.2.1","0.2.10","0.2.11","0.2.12","0.2.13","0.2.14","0.2.15","0.2.16","0.2.2","0.2.3","0.2.4","0.2.5","0.2.6","0.2.7","0.2.8","0.2.9","0.2b1"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/xhtml2pdf/PYSEC-2026-2056.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"}]}