CVE-2025-68616: Weasyprint Ssrf Urlfetcher Redirects
In WeasyPrint before 68.0, URL fetching allowed automatic HTTP redirects, potentially bypassing SSRF protections when using custom URL fetchers. `default_url_fetcher` is vulnerable and deprecated. Use `URLFetcher` with `allow_redirects=False` to securely control redirection and prevent SSRF bypasses.
greprules fetch cve-2025-68616-weasyprint-ssrf-urlfetcher-redirects --engine opengrepDescription
In WeasyPrint before 68.0, URL fetching allowed automatic HTTP redirects, potentially bypassing SSRF protections when using custom URL fetchers. `default_url_fetcher` is vulnerable and deprecated. Use `URLFetcher` with `allow_redirects=False` to securely control redirection and prevent SSRF bypasses.
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.