CVE-2026-106443

Source
https://cve.org/CVERecord?id=CVE-2026-106443
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-106443.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-106443
Aliases
Downstream
Published
2026-10-06T18:57:43Z
Modified
2026-10-08T02:50:33Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
WeasyPrint: EPS images reach the Ghostscript interpreter resulting in RCE
Details

WeasyPrint helps web developers to create PDF documents. Prior to 70.0, the image-loading path in weasyprint/images.py passes fetched image bytes from HTML img URLs, CSS image values, SVG image references, and data URIs to Pillow's generic image dispatcher without excluding EPS or PostScript formats. On hosts with Ghostscript installed, Pillow EpsImagePlugin invokes the interpreter for attacker-controlled PostScript, which can produce interpreter-permitted effects and can lead to remote code execution when the installed Ghostscript version has a usable sandbox bypass. Hosts without Ghostscript do not reach this rasterization path. This issue is fixed in version 70.0.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-20"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/106xxx/CVE-2026-106443.json"
}
References

Affected packages

Git / github.com/kozea/weasyprint

Affected ranges

Type
GIT
Repo
https://github.com/kozea/weasyprint
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "70.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v0.*
v0.1
v0.10
v0.11
v0.12
v0.13
v0.14
v0.15
v0.16
v0.17
v0.17.1
v0.18
v0.19
v0.19.1
v0.2
v0.20
v0.20.1
v0.24
v0.25
v0.26
v0.27
v0.28
v0.29
v0.30
v0.31
v0.32
v0.33
v0.34
v0.35
v0.36
v0.37
v0.38
v0.39
v0.40
v0.41
v0.42
v0.5
v0.6
v0.7
v0.8
v0.9
Other
v43
v43rc1
v43rc2
v44
v45
v46
v47
v48
v49
v50
v51
v53.*
v53.0
v53.0b1
v53.0b2
v54.*
v54.0
v54.0b1
v55.*
v55.0b1
v56.*
v56.0b1
v57.*
v57.0
v57.0b1
v57.1
v58.*
v58.0
v58.0b1
v58.1
v59.*
v59.0
v59.0b1
v60.*
v60.0
v60.1
v61.*
v61.0
v61.1
v62.*
v62.0
v62.1
v63.*
v63.0
v63.1
v64.*
v64.0
v64.1
v65.*
v65.0
v66.*
v66.0
v67.*
v67.0
v68.*
v68.0
v68.1
v69.*
v69.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-106443.json"