CVE-2026-106443
Last modified
CVE-2026-106443 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. WeasyPrint helps web developers to create PDF documents. Prior to 70.0, the image-loading path in weasyprint/images.py passes fetched image bytes from HTML img URLs, CSS image values, SVG image references, and data URIs to Pillow's generic image dispatcher without excluding EPS or PostScript formats.
Description
WeasyPrint helps web developers to create PDF documents. Prior to 70.0, the image-loading path in weasyprint/images.py passes fetched image bytes from HTML img URLs, CSS image values, SVG image references, and data URIs to Pillow's generic image dispatcher without excluding EPS or PostScript formats. On hosts with Ghostscript installed, Pillow EpsImagePlugin invokes the interpreter for attacker-controlled PostScript, which can produce interpreter-permitted effects and can lead to remote code execution when the installed Ghostscript version has a usable sandbox bypass. Hosts without Ghostscript do not reach this rasterization path. This issue is fixed in version 70.0.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-106443?
How severe is CVE-2026-106443?
How do I fix CVE-2026-106443?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-10643Zephyr's IP socket recvmsg() implementation (subsys/net/lib/…7.8
- CVE-2026-106439Hydra is a framework for elegantly configuring complex appli…8.5
- CVE-2026-10644The Microchip SERCOM-G1 UART driver (drivers/serial/uart_mch…3.1
- CVE-2026-106440Hydra is a framework for elegantly configuring complex appli…7.8
- CVE-2026-106441Hydra is a framework for elegantly configuring complex appli…7.8
- CVE-2026-106442Hydra is a framework for elegantly configuring complex appli…7.8
- CVE-2026-106444Handlebars provides the power necessary to let users build s…4.7
- CVE-2026-106445Handlebars provides the power necessary to let users build s…9.2
- CVE-2026-106446Handlebars provides the power necessary to let users build s…9.8
- CVE-2026-106447StableLib is a stable library of useful TypeScript and JavaS…8.7
- CVE-2026-106448StableLib is a stable library of useful TypeScript and JavaS…8.9
- CVE-2026-106449yawkat LZ4 Java provides LZ4 compression for Java. Prior to …3.7
Are you affected by CVE-2026-106443?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
