From 80601cc013c49969fefc35bfd18ca6bcfb21ccbd Mon Sep 17 00:00:00 2001 From: Raphael Michel Date: Tue, 9 Jun 2026 19:32:56 +0200 Subject: [PATCH] [SECURITY] Disable outbound and file access for reportlab (CVE-2026-57535) --- src/pretix/helpers/apps.py | 5 +++ src/tests/helpers/test_reportlab.py | 52 +++++++++++++++++++++++++++++ 2 files changed, 57 insertions(+) create mode 100644 src/tests/helpers/test_reportlab.py diff --git a/src/pretix/helpers/apps.py b/src/pretix/helpers/apps.py index c51aa3ed3..a2ef2d7d9 100644 --- a/src/pretix/helpers/apps.py +++ b/src/pretix/helpers/apps.py @@ -29,3 +29,8 @@ class PretixHelpersConfig(AppConfig): def ready(self): from .monkeypatching import monkeypatch_all_at_ready monkeypatch_all_at_ready() + + # Ensure reportlab does not make any calls to the internet + from reportlab import rl_config + rl_config.trustedHosts = [] + rl_config.trustedSchemes = ['data'] diff --git a/src/tests/helpers/test_reportlab.py b/src/tests/helpers/test_reportlab.py new file mode 100644 index 000000000..dcd8f0f5a --- /dev/null +++ b/src/tests/helpers/test_reportlab.py @@ -0,0 +1,52 @@ +# +# This file is part of pretix (Community Edition). +# +# Copyright (C) 2014-2020 Raphael Michel and contributors +# Copyright (C) 2020-today pretix GmbH and contributors +# +# This program is free software: you can redistribute it and/or modify it under the terms of the GNU Affero General +# Public License as published by the Free Software Foundation in version 3 of the License. +# +# ADDITIONAL TERMS APPLY: Pursuant to Section 7 of the GNU Affero General Public License, additional terms are +# applicable granting you additional permissions and placing additional restrictions on your usage of this software. +# Please refer to the pretix LICENSE file to obtain the full terms applicable to this work. If you did not receive +# this file, see . +# +# This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied +# warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU Affero General Public License for more +# details. +# +# You should have received a copy of the GNU Affero General Public License along with this program. If not, see +# . +# +import pytest +from reportlab.platypus import Paragraph + + +def test_http_access_disabled(monkeypatch): + def guard(*args, **kwargs): + pytest.fail("No internet wanted!") + + monkeypatch.setattr('socket.socket', guard) + + with pytest.raises(OSError, match="Cannot open resource"): + Paragraph( + '', + ) + + +def test_file_access_disabled_scheme(monkeypatch): + with pytest.raises(OSError, match="Cannot open resource"): + Paragraph( + '', + ) + + +@pytest.mark.xfail +def test_file_access_disabled_direct(monkeypatch): + # Unfortunately this is not prevented by the reprotlab config, but the risk is low since only valid images + # can be used. + with pytest.raises(OSError, match="Cannot open resource"): + Paragraph( + '', + )