What is CVE-2026-71270?
A Server-Side Request Forgery (SSRF) vulnerability was found in Stirling-PDF's `/api/v1/convert/url/pdf` endpoint. While SSRF protections were added to sibling endpoints, this endpoint was not updated, leaving it exposed. It allows unauthorized requests to internal resources via remote URLs, requiring an immediate update.
Azərbaycanca: Stirling-PDF-in `/api/v1/convert/url/pdf` endpoint-də Server-Side Request Forgery (SSRF) zəifliyi aşkar edilib. Digər əlaqəli endpoint-lərə SSRF qorunması əlavə edilsə də, bu hissə yenilənmədiyi üçün təsirə məruz qalıb. İstismar zamanı uzaqdan URL vasitəsilə daxili şəbəkə resurslarına icazəsiz sorğu göndərmək mümkündür, dərhal yeniləmə tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
In which endpoint of Stirling-PDF was CVE-2026-71270 discovered?
The Server-Side Request Forgery (SSRF) vulnerability was discovered in the `/api/v1/convert/url/pdf` endpoint of Stirling-PDF.
What happens when CVE-2026-71270 is exploited?
When exploited, it allows unauthorized requests to be sent to internal resources via remote URLs.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.