CVE-2025-55150

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
11/08/2025
Last modified:
15/08/2025

Description

Stirling-PDF is a locally hosted web application that performs various operations on PDF files. Prior to version 1.1.0, when using the /api/v1/convert/html/pdf endpoint to convert HTML to PDF, the backend calls a third-party tool to process it and includes a sanitizer for security sanitization which can be bypassed and result in SSRF. This issue has been patched in version 1.1.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:stirlingpdf:stirling_pdf:*:*:*:*:*:*:*:* 1.1.0 (excluding)