CVE-2026-57535 Details
Description
Content injected to PDF rendering contexts could, in many places, include HTML content including <img> tags. If the src attribute of these images pointed to an URL, the PDF rendering engine would download the image from that place and display it, thereby leaking information about the rendering server and possibly creating an SSRF vector in the local network.
A vulnerability exists in the PDF rendering process of Pretix, where injected HTML content, including image tags, could be exploited. If the 'src' attribute of the images pointed to a URL, the PDF rendering engine would download and display the image. This behavior could leak information about the server rendering the PDF and potentially create a server-side request forgery (SSRF) vulnerability, allowing access to the local network.
Users are advised to update to Pretix versions 2026.5.2, 2026.4.4, or 2026.3.4, all of which include the necessary fix. For those using the Pretix PDF rendering feature, be aware that this vulnerability could have altered the rendering of certain documents, such as invoices, which previously depended on HTML tags being rendered. This was not intended or documented behavior.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 25, 2026CISA-ADP
Assessed Jun 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://pretix.eu/about/en/blog/20260625-release-2026-5-2/ | rami.io | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-80 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) | rami.io |
Affected Products
| Product | Versions |
|---|---|
| pretix | >= 2026, < 2026.5.2 >= 2026, < 2026.4.4 >= 2026, < 2026.3.4 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 25, 2026 | CVE Modified | CISA-ADP |
| Jun 25, 2026 | New CVE Received | rami.io |
Volerion