<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T14:21:03.690115+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-68523</id>
    <title>CVE-2026-68523 — Fulgur: Unbounded page slicing from attacker-controlled CSS height causes denial of service</title>
    <updated>2026-10-04T14:21:03.720719+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> fulgur-rs fulgur</p>
<p>`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In versions prior to 0.19.0, a body-direct child whose CSS-resolved height greatly exceeds the page height was sliced into one fragment per page with no upper bound. This is fixed in 0.19.0. A `MAX_PAGES` cap bounds the slice loop — halting it even
for a `+inf` height — and non-finite layout heights are sanitized so they can no longer drive the loop. As a workaround, validate or constrain untrusted CSS (in particular `height` / `vh` on body-level elements) before passing HTML to fulgur.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-68523"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-j5cx-ph8g-95v3</id>
    <title>GHSA-j5cx-ph8g-95v3 — Fulgur: Unbounded page slicing from attacker-controlled CSS height causes denial of service</title>
    <updated>2026-10-04T14:21:03.720782+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: fulgur</p>
<p>`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that
processes input supplied by many tenants. In versions prior to 0.19.0, a
body-direct child whose CSS-resolved height greatly exceeds the page height was
sliced into one fragment per page with **no upper bound**.</p>
<p>The height is taken directly from attacker-controlled HTML/CSS (`height`, `vh`
units), so a few bytes such as:</p>
<p>```html
&lt;div style="height:99999999px"&gt;&lt;/div&gt;
```</p>
<p>forced on the order of 125,000 page fragments. The pagination code then
allocates `vec![Vec::new(); page_count]` and runs a per-page render loop,
resulting in CPU and memory exhaustion. A non-finite height (one that resolves
to `+inf`) additionally made the slicing loop's `remaining -= last_slice_h`
decrement never terminate, causing an infinite loop.</p>
<p>An attacker able to submit HTML/CSS to a fulgur-based conversion service can
trigger this with a trivially small payload, denying service to the host and
any co-tenants.</p>
<p>## Patches</p>
<p>Fixed in **0.19.0**. A `MAX_PAGES` cap bounds the slice loop — halting it even
for a `+inf` height — and non-finite layout heights are sanitized so they can no
longer drive the loop.</p>
<p>## Workarounds</p>
<p>Upgrade to 0.19.0 or later. If upgrading is not immediately possible, validate
or constrain untrusted CSS (in particular `height` / `vh` on body-level
elements) before passing HTML to fulgur.</p>
<p>## Attack Vector rationale</p>
<p>`fulgur` performs no network I/O of its own; it renders HTML/CSS handed to it by
the embedd…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-j5cx-ph8g-95v3"/>
  </entry>
</feed>
