CVE-2026-49452 | Kozea WeasyPrint up to 68.x CSS Processing __init__.py tinycss2.parse_blocks_contents Background server-side request forgery

SecurityVulns

A vulnerability labeled as critical has been found in Kozea WeasyPrint up to 68.x. Affected by this issue is the function tinycss2.parse_blocks_contents of the file weasyprint/css/__init__.py of the component CSS Processing. Such manipulation of the argument Background leads to server-side request forgery.

This vulnerability is listed as CVE-2026-49452. The attack may be performed from remote. There is no available exploit.

The affected component should be upgraded.VulDB Recent EntriesRead More