THREAT OPS › Threat News › [GHSA] GHSA-jf6q-chmf-3h3v (medium) — weasyprint Has Server-Side Request Forgery (SSRF)
[GHSA] GHSA-jf6q-chmf-3h3v (medium) — weasyprint Has Server-Side Request Forgery (SSRF)
GHSA-jf6q-chmf-3h3v Severity: medium CVE: CVE-2026-55073
weasyprint Has Server-Side Request Forgery (SSRF)
## Summary
`url_fetcher` is WeasyPrint's documented mechanism for restricting resource loading - applications use it to block `file://`, internal hosts, etc. when rendering untrusted input.
Two `write_pdf()` channels ignore the document's `url_fetcher` and build a fresh default `URLFetche
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- 2945986160dedd97a7547be03805b667964e422asha1
- CVE-2026-55073cve
Original source: https://github.com/advisories/GHSA-jf6q-chmf-3h3v