CVE-2026-49359 | pontedilana php-weasyprint up to 2.5.x file_get_contents server-side request forgery (GHSA-c5fp-p67m-gq56)

SecurityVulns

A vulnerability classified as critical was found in pontedilana php-weasyprint up to 2.5.x. The impacted element is the function file_get_contents. The manipulation results in server-side request forgery.

This vulnerability is identified as CVE-2026-49359. The attack can be executed remotely. There is not any exploit available.

Upgrading the affected component is advised.VulDB Recent EntriesRead More