CVE-2026-71270

Summary

Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated with the CustomHtmlSanitizer/SsrfProtectionService SSRF protections that were added to three sibling conversion endpoints (html/pdf, file/pdf, markdown/pdf).

Affected Software

VendorProductVersion RangeStatus
Stirling-ToolsStirling-PDF0 <= *affected

Weaknesses

  • CWE-918: CWE-918

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References