Bug 2522064 - CVE-2026-49452 weasyprint: WeasyPrint: CSS Injection via Presentational Hints [epel-all]
Summary: CVE-2026-49452 weasyprint: WeasyPrint: CSS Injection via Presentational Hints...
Keywords:
Status: NEW
Alias: None
Product: Fedora EPEL
Classification: Fedora
Component: weasyprint
Version: epel10
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Felix Schwarz
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["1f2aa2bb-1391-4eb0-874d-a...
Depends On:
Blocks: CVE-2026-49452
TreeView+ depends on / blocked
 
Reported: 2026-08-24 16:36 UTC by Laura Pardo
Modified: 2026-08-24 16:36 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Laura Pardo 2026-08-24 16:36:59 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

WeasyPrint helps web developers to create PDF documents. Prior to 69.0, WeasyPrint embeds unescaped HTML presentational-hint attribute values into CSS in weasyprint/css/__init__.py when presentational_hints=True. The background attribute is inserted into a background-image:url() declaration and parsed by tinycss2.parse_blocks_contents(), allowing untrusted HTML to inject additional CSS declarations. Applications that render untrusted HTML with presentational hints enabled can be affected by CSS injection and server-side requests through injected url() values. This issue is fixed in version 69.0.


Note You need to log in before you can comment on or make changes to this bug.