PT-2026-95099 · Fulgur · Fulgur
CVE-2026-68537
·
Published
2026-07-05
·
Updated
2026-09-17
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
fulgur versions prior to 0.26.0
Description
fulgur converts untrusted HTML/CSS into PDF. A flaw exists where a childless box resolving to a pathologically tall height can be amplified into thousands of blank PDF pages, even without visible output. This occurs because the childless-collapse defense was gated by a tag-only replaced content check, allowing non-painting replaced elements to bypass it. Examples of such elements include an unresolved
src, a visibility:hidden image, an undecodable image format, or an empty <svg>. A trailing-sibling variant of this issue also exists.This behavior allows a small HTML payload to generate up to 10,000 blank pages (defined by
MAX PAGES), leading to CPU and memory exhaustion and resulting in a denial of service for the host and other tenants. In versions prior to 0.19.0, the lack of a page-count cap allowed for an unbounded number of pages and non-terminating loops when encountering non-finite layout heights.Recommendations
Update to version 0.26.0 or later.
As a temporary workaround, validate or constrain untrusted CSS, specifically restricting very large
height or vh values on elements before passing HTML to the software.Exploit
Fix
Resource Exhaustion
Infinite Loop
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fulgur