for a `+inf` height — and non-finite layout heights are sanitized so they can no longer drive the loop. As a workaround, validate or constrain untrusted CSS (in particular `height` / `vh` on body-level elements) before passing HTML to fulgur.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-j5cx-ph8g-95v3 | Fulgur: Unbounded page slicing from attacker-controlled CSS height causes denial of service |
Thu, 17 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | `fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In versions prior to 0.19.0, a body-direct child whose CSS-resolved height greatly exceeds the page height was sliced into one fragment per page with no upper bound. This is fixed in 0.19.0. A `MAX_PAGES` cap bounds the slice loop — halting it even for a `+inf` height — and non-finite layout heights are sanitized so they can no longer drive the loop. As a workaround, validate or constrain untrusted CSS (in particular `height` / `vh` on body-level elements) before passing HTML to fulgur. | |
| Title | Fulgur: Unbounded page slicing from attacker-controlled CSS height causes denial of service | |
| Weaknesses | CWE-400 CWE-835 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-17T20:23:23.616Z
Reserved: 2026-07-30T16:19:08.082Z
Link: CVE-2026-68523
No data.
Status : Received
Published: 2026-09-17T21:17:19.127
Modified: 2026-09-17T21:17:19.127
Link: CVE-2026-68523
No data.
OpenCVE Enrichment
No data.
Github GHSA