{"id":"UBUNTU-CVE-2025-68616","details":"WeasyPrint helps web developers to create PDF documents. Prior to version 68.0, a server-side request forgery (SSRF) protection bypass exists in WeasyPrint's `default_url_fetcher`. The vulnerability allows attackers to access internal network resources (such as `localhost` services or cloud metadata endpoints) even when a developer has implemented a custom `url_fetcher` to block such access. This occurs because the underlying `urllib` library follows HTTP redirects automatically without re-validating the new destination against the developer's security policy. Version 68.0 contains a patch for the issue.","modified":"2026-06-30T18:15:53.467291422Z","published":"2026-01-19T16:15:00Z","upstream":["CVE-2025-68616"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-68616"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2025-68616"},{"type":"REPORT","url":"https://github.com/Kozea/WeasyPrint/security/advisories/GHSA-983w-rhvv-gwmv"}],"affected":[{"package":{"name":"weasyprint","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/weasyprint?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["50-2","51-1","51-2"],"ecosystem_specific":{"binaries":[{"binary_name":"weasyprint","binary_version":"51-2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-68616.json"}},{"package":{"name":"weasyprint","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/weasyprint?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["51-2","51-3","53.4-1","54.0-1","54.1-1"],"ecosystem_specific":{"binaries":[{"binary_name":"weasyprint","binary_version":"54.1-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-68616.json"}},{"package":{"name":"weasyprint","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/weasyprint?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["59.0-1","60.2-1","61.0-1","61.1-1"],"ecosystem_specific":{"binaries":[{"binary_name":"weasyprint","binary_version":"61.1-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-68616.json"}},{"package":{"name":"weasyprint","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/weasyprint?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["62.3-1"],"ecosystem_specific":{"binaries":[{"binary_name":"weasyprint","binary_version":"62.3-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-68616.json"}},{"package":{"name":"weasyprint","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/weasyprint?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["62.3-1","62.3-1build1","67.0-1"],"ecosystem_specific":{"binaries":[{"binary_name":"weasyprint","binary_version":"67.0-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-68616.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"Ubuntu","score":"medium"}]}