All versions of package reportlab at time of writing are vulnerable to Server-side Request Forgery (SSRF) via img tags. In order to reduce risk, use trustedSchemes & trustedHosts (see in Reportlab's documentation)
Steps to reproduce by Karan Bamal:
<img src="http://127.0.0.1:5000" valign="top"/>nc -lp 5000{
"cwe_ids": [
"CWE-918"
],
"github_reviewed": true,
"github_reviewed_at": "2021-03-19T22:04:29Z",
"nvd_published_at": "2021-02-18T16:15:00Z",
"severity": "HIGH"
}