PT-2026-95107 · Fulgur · Fulgur

CVE-2026-68523

·

Published

2026-07-05

·

Updated

2026-09-21

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions fulgur versions prior to 0.19.0
Description An issue exists when converting untrusted HTML/CSS into PDF where a body-direct child with a CSS-resolved height significantly exceeding the page height is sliced into fragments per page without an upper bound. Because the height is derived from attacker-controlled CSS using the height or vh variables, a small payload can force the allocation of a massive number of page fragments, leading to CPU and memory exhaustion. Additionally, a non-finite height resolving to +inf can cause the slicing loop to never terminate, resulting in an infinite loop. This allows an attacker to trigger a denial of service for the host and other tenants.
Recommendations Update to version 0.19.0 or later. As a temporary workaround, validate or constrain untrusted CSS, specifically the height and vh variables on body-level elements, before passing HTML to the software.

Exploit

Fix

Infinite Loop

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-68523
GHSA-J5CX-PH8G-95V3
RUSTSEC-2026-0200

Affected Products

Fulgur