Summary
CVE-2026-71270 is a Server-Side Request Forgery (SSRF) vulnerability (CWE-918) in Stirling-PDF, a self-hosted web application for performing operations on PDF files. The flaw resides in the POST /api/v1/convert/url/pdf endpoint, which lacks the SSRF protections present in sibling conversion endpoints, allowing an unauthenticated attacker to retrieve cloud metadata and internal network resources. It carries a CVSS v3.1 base score of 8.6 (High).
Technical details
- Root cause: The
/api/v1/convert/url/pdfendpoint (implemented inConvertWebsiteToPDF.java) validates only the initial URL resolution to public IPs but does not sanitize embedded resource references in the fetched HTML. The WeasyPrint subprocess that renders the page then processes those references without per-resource SSRF filtering. - Trigger conditions: An attacker supplies a target webpage containing malicious embedded resource references, which the server fetches and processes when generating the PDF.
- Attack vector: Network (AV:N); no authentication (PR:N) and no user interaction (UI:N) required.
- Impact: High confidentiality impact. Data from cloud metadata endpoints (e.g.,
169.254.169.254) or internal networks can be leaked into the generated PDF. The CVSS vector indicates a scope change (S:C) with no integrity or availability impact.
Affected software
- Stirling-PDF: all versions (marked affected from version 0 onward per the CVE record).
Severity
- CVSS v3.1 Base Score: 8.6 (High)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate: No patched version is listed in the CVE record at time of writing. Monitor the Stirling-Tools GitHub repository and security advisories for an official fix and upgrade as soon as one is published.
- If no patch: Restrict the Stirling-PDF host’s egress so it cannot reach internal subnets, link-local addresses, or cloud metadata services (e.g.,
169.254.169.254) at the network or container layer. Run Stirling-PDF in an isolated network segment with no route to sensitive internal services, and disable or block the URL-to-PDF conversion endpoint if it is not required.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Page title:
Stirling-PDF - Raw response body:
window.stirlingPDF = window.stirlingPDF || {},stirlingPDFLabel = "Stirling-PDF"

