PT-2026-95099 · Fulgur · Fulgur

CVE-2026-68537

·

Published

2026-07-05

·

Updated

2026-09-17

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions fulgur versions prior to 0.26.0
Description fulgur converts untrusted HTML/CSS into PDF. A flaw exists where a childless box resolving to a pathologically tall height can be amplified into thousands of blank PDF pages, even without visible output. This occurs because the childless-collapse defense was gated by a tag-only replaced content check, allowing non-painting replaced elements to bypass it. Examples of such elements include an unresolved src, a visibility:hidden image, an undecodable image format, or an empty <svg>. A trailing-sibling variant of this issue also exists.
This behavior allows a small HTML payload to generate up to 10,000 blank pages (defined by MAX PAGES), leading to CPU and memory exhaustion and resulting in a denial of service for the host and other tenants. In versions prior to 0.19.0, the lack of a page-count cap allowed for an unbounded number of pages and non-terminating loops when encountering non-finite layout heights.
Recommendations Update to version 0.26.0 or later. As a temporary workaround, validate or constrain untrusted CSS, specifically restricting very large height or vh values on elements before passing HTML to the software.

Exploit

Fix

Resource Exhaustion

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-68537
GHSA-4RF6-QX84-Q9FV
RUSTSEC-2026-0201

Affected Products

Fulgur