Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-68616

31
FAUCET Score

CVE-2025-68616 describes a server-side request forgery (SSRF) protection bypass in WeasyPrint versions prior to 68.0, affecting the kozea weasyprint product. This vulnerability allows attackers to access internal network resources, even when custom security policies are in place, due to automatic HTTP redirects by the underlying urllib library. With a CVSS score of 7.5 (HIGH), it has a network attack vector and low attack complexity, potentially leading to high confidentiality impact. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion with 10 mentions, indicating awareness and potential future exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
< 68.0CPE matchmatch criteria
cpe:2.3:a:kozea:weasyprint:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.50%
Probability of exploitation in next 30 days
EPSS Percentile
40.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0050 is in the 18th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: weasyprintFixed in: 68.0
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: ansible-automation-platform-tech-preview/automation-dashboard-rhel9

Vendor Advisories (2)

pipGHSA-983w-rhvv-gwmvhigh

WeasyPrint has a Server-Side Request Forgery (SSRF) Protection Bypass via HTTP Redirect

Jan 20, 2026
redhatCVE-2025-68616Important

WeasyPrint: WeasyPrint Server-Side Request Forgery (SSRF)

Jan 19, 2026

References

access.redhat.com / security/cve/CVE-2025-68616
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2025/cve-2025-68616.json
github.com / Kozea/WeasyPrint/commit/b6a14f0f3f4ce9c0c75c1a2d73cb1c5d43f0e565
Patch
github.com / Kozea/WeasyPrint/security/advisories/GHSA-983w-rhvv-gwmv
ExploitThird Party Advisory