CVE-2026-68523: CWE-400: Uncontrolled Resource Consumption in fulgur-rs fulgur
`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In versions prior to 0.19.0, a body-direct child whose CSS-resolved height greatly exceeds the page height was sliced into one fragment per page with no upper bound. This is fixed in 0.19.0. A `MAX_PAGES` cap bounds the slice loop — halting it even for a `+inf` height — and non-finite layout heights are sanitized so they can no longer drive the loop. As a workaround, validate or constrain untrusted CSS (in particular `height` / `vh` on body-level elements) before passing HTML to fulgur.
AI Analysis
Technical Summary
The fulgur library converts untrusted HTML/CSS into PDF, often in multi-tenant server environments. In versions before 0.19.0, if a body-direct child element's CSS-resolved height is extremely large, the library slices the content into one fragment per page with no upper bound, causing uncontrolled resource consumption (CWE-400). This vulnerability is addressed in version 0.19.0 by adding a MAX_PAGES cap to limit the slicing loop and sanitizing non-finite layout heights to prevent infinite loops. As a workaround, input CSS should be validated or constrained, particularly the height and viewport height (vh) properties on body-level elements.
Potential Impact
Exploitation of this vulnerability can cause denial of service by exhausting server resources during PDF generation, impacting availability. There is no impact on confidentiality or integrity. The CVSS v3.1 score is 7.5 (high), reflecting network attack vector, low complexity, no privileges or user interaction required, and an impact limited to availability.
Mitigation Recommendations
This vulnerability is fixed in fulgur version 0.19.0. Users should upgrade to version 0.19.0 or later to apply the official fix. Until upgrading, it is recommended to validate or constrain untrusted CSS input, especially height and vh properties on body-level elements, to prevent excessive resource consumption. No other vendor advisories or patches are indicated. There is no indication of known exploits in the wild.
CVE-2026-68523: CWE-400: Uncontrolled Resource Consumption in fulgur-rs fulgur
Description
`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In versions prior to 0.19.0, a body-direct child whose CSS-resolved height greatly exceeds the page height was sliced into one fragment per page with no upper bound. This is fixed in 0.19.0. A `MAX_PAGES` cap bounds the slice loop — halting it even for a `+inf` height — and non-finite layout heights are sanitized so they can no longer drive the loop. As a workaround, validate or constrain untrusted CSS (in particular `height` / `vh` on body-level elements) before passing HTML to fulgur.
CVSS v3.1
Score 7.5high
Affected software
fulgur-rs
fulgur
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The fulgur library converts untrusted HTML/CSS into PDF, often in multi-tenant server environments. In versions before 0.19.0, if a body-direct child element's CSS-resolved height is extremely large, the library slices the content into one fragment per page with no upper bound, causing uncontrolled resource consumption (CWE-400). This vulnerability is addressed in version 0.19.0 by adding a MAX_PAGES cap to limit the slicing loop and sanitizing non-finite layout heights to prevent infinite loops. As a workaround, input CSS should be validated or constrained, particularly the height and viewport height (vh) properties on body-level elements.
Potential Impact
Exploitation of this vulnerability can cause denial of service by exhausting server resources during PDF generation, impacting availability. There is no impact on confidentiality or integrity. The CVSS v3.1 score is 7.5 (high), reflecting network attack vector, low complexity, no privileges or user interaction required, and an impact limited to availability.
Mitigation Recommendations
This vulnerability is fixed in fulgur version 0.19.0. Users should upgrade to version 0.19.0 or later to apply the official fix. Until upgrading, it is recommended to validate or constrain untrusted CSS input, especially height and vh properties on body-level elements, to prevent excessive resource consumption. No other vendor advisories or patches are indicated. There is no indication of known exploits in the wild.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-07-30T16:19:08.082Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aac51e755bf5e2cf5e0cf1f
Added to database: 09/17/2026, 20:47:35 UTC
Last enriched: 09/17/2026, 21:02:35 UTC
Last updated: 09/18/2026, 01:55:42 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.