{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/fulgur--0.19.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:fulgur-rs:fulgur:*:*:*:*:*:rust:*:*"],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["fulgur (\u003c 0.26.0)","fulgur (\u003c 0.19.0)"],"_cs_severities":["medium"],"_cs_tags":["denial-of-service","vulnerability","rust"],"_cs_type":"advisory","_cs_vendors":["fulgur-rs"],"content_html":"\u003cp\u003eFulgur is a Rust-based library for converting HTML/CSS into PDF documents. Versions prior to 0.26.0 contain a critical resource exhaustion vulnerability identified as CVE-2026-68537. The library's existing \u0026quot;childless-collapse\u0026quot; defense, intended to prevent the rendering of excessively large or pathologically tall elements, was flawed because it only checked for tag-specific \u0026quot;replaced content.\u0026quot; Consequently, non-painting replaced elements, such as images with missing sources, hidden visibility, undecodable formats, or empty \u003ccode\u003e\u0026lt;svg\u0026gt;\u003c/code\u003e elements, could bypass this defense.\u003c/p\u003e\n\u003cp\u003eAn attacker can exploit this by submitting a small HTML payload containing these specific elements with pathologically tall height attributes. This forces the renderer to allocate and process up to 10,000 blank pages, leading to significant CPU and memory consumption. In deployments where Fulgur processes untrusted input from network-facing services, this leads to a denial of service for the host and any co-tenants.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a network-facing application that uses the Fulgur library to generate PDFs from user-provided HTML.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTML payload containing a childless box (e.g., \u003ccode\u003e\u0026lt;img src=\\\u0026quot;\\\u0026quot;\u0026gt;\u003c/code\u003e or \u003ccode\u003e\u0026lt;svg\u0026gt;\u003c/code\u003e) with an extreme CSS \u003ccode\u003eheight\u003c/code\u003e value.\u003c/li\u003e\n\u003cli\u003eThe attacker submits the payload to the target application's PDF generation endpoint.\u003c/li\u003e\n\u003cli\u003eThe application passes the untrusted HTML/CSS to the vulnerable Fulgur library (versions \u0026lt; 0.26.0).\u003c/li\u003e\n\u003cli\u003eThe library's rendering engine encounters the non-painting replaced element and fails to trigger the childless-collapse logic due to the flawed tag-only check.\u003c/li\u003e\n\u003cli\u003eThe renderer attempts to allocate and process the large number of pages defined by the malicious CSS.\u003c/li\u003e\n\u003cli\u003eSystem resources (CPU and memory) are exhausted, leading to service degradation or total crash.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a denial-of-service condition, impacting the availability of the host application. In multi-tenant environments, this impact extends to other users sharing the same server infrastructure. The attack is highly effective as it requires only a few bytes of HTML input to trigger maximum resource allocation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and development teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the Fulgur library to version 0.26.0 or later immediately, as this version removes the flawed tag-only gate and correctly collapses all pathologically tall boxes.\u003c/li\u003e\n\u003cli\u003eIf immediate patching is not feasible, implement strict input validation for untrusted HTML/CSS before passing it to the library. Specifically, constrain or sanitize large height and \u003ccode\u003evh\u003c/code\u003e CSS units.\u003c/li\u003e\n\u003cli\u003eReview applications using Fulgur for exposure to user-supplied HTML and ensure that rendering tasks are performed within containerized or sandboxed environments to limit resource impact.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-17T19:10:31Z","date_published":"2026-09-17T19:10:23Z","id":"https://feed.craftedsignal.io/briefs/2026-09-fulgur-dos/","summary":"Fulgur versions prior to 0.26.0 are vulnerable to a denial-of-service attack where an attacker-supplied HTML payload causes CPU and memory exhaustion by forcing the rendering of thousands of blank PDF pages.","title":"Fulgur HTML-to-PDF Denial of Service via Resource Exhaustion","url":"https://feed.craftedsignal.io/briefs/2026-09-fulgur-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Fulgur (\u003c 0.19.0)","version":"https://jsonfeed.org/version/1.1"}