Build1 distinct publisher3 min readPublished
An archived binary with an SSRF advisory and no fixed version turns a patch ticket into a template re-approval project. Picking the replacement engine is the cheap part.
The Engineer · Build desk
Compiled by The EngineerSomething wrong?How this is made
A vulnerability scanner does not care that the binary still renders. It matches an installed package against an advisory, and CVE-2022-35583 has no fixed version to match against, because there will never be another release [1][2]. That is the whole mechanism: the remediation field on the ticket cannot be filled with a version number, so it gets filled with either an exception that returns at the next audit or a migration [3]. The advisory identifier carries a 2022 prefix, so it was already outstanding when the repository went read-only on 2 January 2023 [15].
The cost of that migration is not in the engine call. It is in the documents. Vitalii, the PDFik founder who wrote the field guide, is direct about the part a vendor post could easily skip: no Chromium-based engine reproduces wkhtmltopdf output pixel for pixel, because line breaking and font fallback differ, so golden files get re-approved [7][13]. The systems most likely to be running the old binary are invoice, report and ticket generators older than five years [6]. Those are the documents somebody formally signed off on, quite possibly the same function now demanding the CVE be closed. Templates using `--toc` or `--outline` need a separate line item, since there is no first-class Chromium equivalent and outlines are either rebuilt in post-processing or abandoned [8].
The engine question then collapses to whether templates need JavaScript to render. If they do not, and the stack is Python, WeasyPrint is a CSS `@page` engine with no browser process at all and active maintenance [9]. If they do, Playwright's five lines of `page.pdf()` arrive with a browser fleet attached: per-tab memory ceilings, crash-looping renderers under load, sandboxing, fonts in the image, pool scaling [10]. Gotenberg packages Chromium and LibreOffice behind an HTTP API in a container, which keeps document content inside your own network and leaves you owning capacity planning, upgrades and availability [11].
The rot on the old path is quieter than the CVE but harder to argue with over time. The engine is a patched Qt WebKit from another era, so CSS grid, flexbox gaps and custom properties misrender without error [4]. Distributions have been dropping the package, official builds do not cover current Debian and Ubuntu releases or arm64 well, and Docker images increasingly depend on third-party rebuilds of an unmaintained binary [5]. Anyone moving to arm64 instances hits that before any auditor does.
Treat the guide as what it says it is, a post by the founder of a competing hosted API [13]. The reason to read it anyway is that it sends compliance-heavy document generation to DocRaptor's PrinceXML engine and its SOC 2 and HIPAA-BAA posture rather than to his own product [12], and lists PDFShift, Api2Pdf and PDFMonkey as Chromium-based shortlist candidates with different pricing shapes [14]. Its own framing is that nothing breaks on a schedule, and the gap widens with each new deployment target, audit and CSS feature [16]. What changed is that one of those pressures now generates a ticket no patch can close.
Ranked by verification strength, evidence, and original report placement.
The wkhtmltopdf GitHub repository was archived on January 2, 2023 and is read-only: no maintainers, no releases, no security patches ever.
CVE-2022-35583, an SSRF via rendered content, will never be fixed upstream in wkhtmltopdf.
If a scanner flags CVE-2022-35583 there is no 'upgrade to version X' remediation; the remediation is migration.
No Chromium-based engine reproduces wkhtmltopdf output pixel-for-pixel because of different line breaking and font fallback, so golden files will need re-approval.
The --toc and --outline flags have no first-class Chromium equivalent; outlines must be rebuilt with a post-processing step or done without.
The field guide's author discloses he is Vitalii, founder of PDFik, a hosted URL/HTML-to-PDF API, and says he lists competitors and names them where they are the better fit.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single vendor-authored source; core maintenance facts checkable, comparisons unevidenced
The cluster rests on one dev.to post written by a competing vendor's founder. Its load-bearing facts (repository archived January 2, 2023, an unpatched SSRF advisory with no fixed version, no pixel parity on Chromium, no first-class --toc/--outline equivalent) are specific and externally checkable, and two of them run against the author's commercial interest. Everything comparative — prevalence in legacy dependency trees, distro removals, arm64 gaps, engine suitability, competitor pricing shapes and compliance posture — is asserted without data, releases, benchmarks or citations.
No migration or usage data supplied
The source documents upstream maintenance status and lists replacement options, but supplies no counts of affected deployments, no distro package removal records, no download or usage figures, and no evidence that any organisation has migrated off wkhtmltopdf or onto WeasyPrint, Gotenberg, Playwright, DocRaptor or the hosted alternatives. The two observations captured here concern project maintenance and an advisory, not adoption, so an adoption score cannot be measured without guessing.
Urgency framing runs slightly ahead of the evidence, but the source hedges itself
The headline framing ('your scanner will only accept migration') pushes a patch-ticket problem into a project-scale mandate, and the packaging-rot and browser-fleet-burden passages assert decay and operational pain without naming distributions, releases or incidents — framing that happens to route readers toward hosted APIs including the author's own. The gap is modest rather than large because the underlying archive and advisory facts are real and specific, and the source explicitly says existing PDFs will not stop rendering tomorrow while flagging caveats that cost it business.
Author is a competing vendor's founder; disclosed twice, product featured in two of five paths
The guide is written by the founder of PDFik, a hosted HTML-to-PDF API that appears both as a rendering option and as a wkhtmltopdf-compatible CLI migration path, and the piece links to that product's migration map. The conflict is disclosed prominently at the top and restated mid-article, and named competitors are recommended for specific fits, which mitigates but does not remove the commercial interest in framing an unmaintained self-hosted binary and self-run browser fleets as costly.
Moderate on the maintenance facts, low on everything comparative
Confidence is bounded by a single-publisher, single-source cluster with a disclosed commercial interest. The archive date, the permanently unpatched advisory and the two migration caveats are stated precisely enough to act on and are corroborated by internal consistency (a 2022-prefixed advisory outstanding before a January 2023 archive). Engine suitability, packaging decay, prevalence and competitor pricing carry little confidence, and no adoption measurement is possible at all.
build
Cloudflare's agent browser makes a cost argument and skips the cost1 distinct publisher
build
Anthropic's Browser Use hands Claude element refs, and hands you the browser1 distinct publisher
build
Screenshot retrieval gets a one-line install, and the comparison is text embeddings1 distinct publisher
build
Yadda 3's real artifact is not the code, it is the rules the agent could not rewrite1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
dev.to
1 article · August 26, 2026