CVE-2026-71270
EUVD-2026-5335505.08.2026, 13:24
Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated with the CustomHtmlSanitizer/SsrfProtectionService SSRF protections that were added to three sibling conversion endpoints (html/pdf, file/pdf, markdown/pdf).
Awaiting analysis
This vulnerability is currently awaiting analysis.