CVE-2026-71270 Details
Description
Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated with the CustomHtmlSanitizer/SsrfProtectionService SSRF protections that were added to three sibling conversion endpoints (html/pdf, file/pdf, markdown/pdf).
A server-side request forgery (SSRF) vulnerability has been identified in the Stirling-PDF application, specifically within the URL conversion endpoint of the PDF generation API. This vulnerability arises because the endpoint does not implement the same SSRF protections that are present in three other conversion endpoints. The flawed endpoint only checks that the requested URL points to a public IP before fetching the HTML content server-side, which is then passed unsanitized to a WeasyPrint subprocess. Exploitation of this vulnerability allows an attacker to manipulate the fetched HTML to include references to internal network resources or cloud metadata endpoints, which could lead to unauthorized access or leakage of sensitive information into the generated PDF.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 5, 2026CISA-ADP
Assessed Aug 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Stirling-Tools/Stirling-PDF | TuranSec | Source CodeVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | TuranSec |
Affected Products
| Product | Versions |
|---|---|
| Stirling-PDF | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 10, 2026 | CVE Modified | TuranSec |
| Aug 5, 2026 | CVE Modified | CISA-ADP |
| Aug 5, 2026 | New CVE Received | TuranSec |
Volerion