CVE-2025-68616: 
Python vulnerability analysis and mitigation

Overview

CVE-2025-68616 is a Server-Side Request Forgery (SSRF) protection bypass vulnerability in WeasyPrint's default_url_fetcher function. It affects all WeasyPrint versions prior to 68.0 (pip package weasyprint < 68.0) and was disclosed on January 19, 2026. The vulnerability allows unauthenticated remote attackers to access internal network resources — such as localhost services or cloud metadata endpoints — even when developers have implemented custom url_fetcher security policies to block such access. It carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, Red Hat).

Technical details

The root cause is a Time-of-Check to Time-of-Use (TOCTOU) flaw (CWE-918: SSRF; CWE-601: Open Redirect) in weasyprint/urls.py. WeasyPrint's default_url_fetcher uses Python's urllib.request.urlopen, which automatically follows HTTP redirects (301, 302, 307, etc.) without re-invoking the developer's custom url_fetcher validation logic for the redirected destination URL. An attacker supplies a URL that passes the custom blocklist/allowlist check (e.g., using 127.0.0.1 instead of localhost), but that URL immediately redirects to a blocked internal resource; urllib follows the redirect transparently, bypassing the security policy entirely. The fix in version 68.0 disables automatic redirect following in default_url_fetcher (setting allow_redirects=False) and introduces a new URLFetcher class that properly re-validates redirect destinations (GitHub Advisory, Patch Commit).

Impact

Successful exploitation allows unauthenticated remote attackers to perform internal network reconnaissance, accessing services such as Redis, Elasticsearch, or admin panels running on the loopback interface or local network. In cloud environments, attackers can redirect requests to instance metadata services (e.g., http://169.254.169.254) to steal cloud credentials and potentially escalate privileges. The primary impact is high confidentiality loss — sensitive internal data, credentials, and configuration information can be exfiltrated — with no direct integrity or availability impact. Critically, the vulnerability renders custom url_fetcher security controls ineffective, creating a false sense of security for developers who believe their SSRF mitigations are functioning (GitHub Advisory).

Exploitability

A public proof-of-concept (PoC) exploit is available in the official GitHub security advisory, demonstrating the full attack chain using Flask-based redirector and victim services (GitHub Advisory). The vulnerability requires no authentication, no privileges, and no user interaction, making it trivial to exploit with low attack complexity. The EPSS score is approximately 0.032% (0.022% per GitHub Advisory), indicating low current exploitation probability. There is no evidence of active in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability is detectable by Qualys (ID: 760503) and Nessus (IDs: 294937, 297100, 319613) (Feedly).

Exploitation steps

  1. Identify a target: Find a web application or SaaS platform that uses WeasyPrint (versions < 68.0) to render user-supplied HTML/CSS into PDFs, and that has implemented a custom url_fetcher to block internal resource access.
  2. Set up an external redirector: Deploy an attacker-controlled server (e.g., at attacker.com:1337) with an endpoint (e.g., /image.png) that issues an HTTP 302 redirect to the target internal resource (e.g., http://localhost:5000/secret or http://169.254.169.254/latest/meta-data/).
  3. Craft malicious HTML: Create an HTML document referencing the attacker's external URL in a resource tag (e.g., <img src="http://127.0.0.1:1337/image.png"> or as a CSS background-image). Use 127.0.0.1 or another alias to bypass string-based blocklist checks for localhost.
  4. Submit the HTML to WeasyPrint: Trigger PDF generation with the malicious HTML. WeasyPrint's secure_fetcher validates the initial URL (127.0.0.1:1337) and allows it, then calls default_url_fetcher, which uses urllib to fetch the resource.
  5. Exploit the redirect: urllib automatically follows the 302 redirect to the blocked internal resource without re-invoking the custom url_fetcher validation, successfully fetching the internal data.
  6. Extract the data: The internal service's response is embedded in the generated PDF (e.g., as an attachment or rendered content). The attacker retrieves the PDF and extracts the sensitive data using tools like pdfdetach (GitHub Advisory).

Indicators of compromise

  • Network: Outbound HTTP requests from the WeasyPrint server process to internal IP ranges (e.g., 127.0.0.1, 10.x.x.x, 172.16.x.x, 192.168.x.x) or cloud metadata endpoints (169.254.169.254); HTTP redirect chains (301/302/307 responses) from external hosts pointing to internal resources observed in proxy/firewall logs.
  • Logs: Web server or application logs showing PDF generation requests containing external URLs that subsequently trigger connections to internal services; urllib or WeasyPrint debug logs showing redirect-following to internal addresses.
  • File System: Unexpectedly generated PDF files containing embedded attachments or content sourced from internal services; PDF files with pdfdetach-extractable attachments containing internal service responses.
  • Process: Unusual network connections initiated by the Python/WeasyPrint process to loopback (127.0.0.1:*) or link-local (169.254.x.x) addresses during PDF rendering operations (GitHub Advisory).

Mitigation and workarounds

Upgrade WeasyPrint to version 68.0 or later, which patches the vulnerability by disabling automatic redirect following in default_url_fetcher and introducing the new URLFetcher class that properly re-validates redirect destinations (Patch Commit). For environments where immediate patching is not possible, implement network-level egress controls to restrict outbound connections from WeasyPrint processes to internal IP ranges and cloud metadata endpoints. Additionally, migrate custom url_fetcher implementations to use the new URLFetcher class instead of the deprecated default_url_fetcher, and ensure redirect destination URLs are re-validated against security policies. IBM has also issued an advisory for affected EDB PGAI Hybrid Management products (IBM Advisory).

Community reactions

The vulnerability was reported by security researcher g4nkd and published by the WeasyPrint maintainer liZe on January 19, 2026, with a simultaneous patch release (GitHub Advisory). Red Hat tracked the issue via Bugzilla (Bug 2430858) and rated it high severity, with 22 users CC'd on the report (Red Hat Bugzilla). The vulnerability received coverage from security news outlets and was noted on Mastodon by TheHackerWire. Fedora and SUSE issued package updates addressing the vulnerability, and IBM published a security bulletin for affected EDB PGAI products.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

weasyprint

Affected

sid

weasyprint: 69.0-1

Fixed

trixie

weasyprint

Affected

Ubuntu

Unknown

devel

weasyprint

Unknown

focal (esm-apps)

weasyprint

Unknown

jammy

weasyprint

Unknown

jammy (esm-apps)

weasyprint

Unknown

noble

weasyprint

Unknown

noble (esm-apps)

weasyprint

Unknown

resolute

weasyprint

Unknown

resolute (esm-apps)

weasyprint

Unknown

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management