PT-2026-95107 · Fulgur · Fulgur
CVE-2026-68523
·
Published
2026-07-05
·
Updated
2026-09-21
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
fulgur versions prior to 0.19.0
Description
An issue exists when converting untrusted HTML/CSS into PDF where a body-direct child with a CSS-resolved height significantly exceeding the page height is sliced into fragments per page without an upper bound. Because the height is derived from attacker-controlled CSS using the
height or vh variables, a small payload can force the allocation of a massive number of page fragments, leading to CPU and memory exhaustion. Additionally, a non-finite height resolving to +inf can cause the slicing loop to never terminate, resulting in an infinite loop. This allows an attacker to trigger a denial of service for the host and other tenants.Recommendations
Update to version 0.19.0 or later.
As a temporary workaround, validate or constrain untrusted CSS, specifically the
height and vh variables on body-level elements, before passing HTML to the software.Exploit
Fix
Infinite Loop
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fulgur