Reportlab is a Python library for dynamically generating PDF documents, widely embedded in server-side applications and reporting systems; its vulnerability profile centers on the core reportlab product and reflects weaknesses in document generation and data handling, including XML injection, code injection, and server-side request forgery. These weakness classes align with the library's role as a bridge between untrusted input and document output, and defenders should review applications that accept user-controlled content fed to Reportlab's rendering engine. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Reportlab over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-17626CRITICAL ReportLab through 3.5.26 allows remote code execution because of toColor(eval(arg)) in colors.py, as demonstrated by a crafted XML document with '<span color="' followed by arbitra | Oct 16, 2019 | 9.8 | 36 | NO | NO |
CVE-2019-19450CRITICAL paraparser in ReportLab before 3.5.31 allows remote code execution because start_unichar in paraparser.py evaluates untrusted user input in a unichar element in a crafted XML docum | Sep 20, 2023 | 9.8 | 33 | NO | NO |
CVE-2023-33733HIGH Reportlab up to v3.6.12 allows attackers to execute arbitrary code via supplying a crafted PDF file. | Jun 5, 2023 | 7.8 | 26 | NO | NO |
CVE-2020-28463MEDIUM All versions of package reportlab are vulnerable to Server-side Request Forgery (SSRF) via img tags. In order to reduce risk, use trustedSchemes & trustedHosts (see in Reportlab's | Feb 18, 2021 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Reportlab.
Media articles that mention a CVE ID that affects a product developed by Reportlab — matched by CVE ID, not by vendor name.