Sceawere

Vulnerability Detail

CVE-2026-108554UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

PDFMathTranslate SSRF Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
3h ago
Vendor
PDFMathTranslate
Product
PDFMathTranslate
Attack Type
Server-Side Request Forgery (SSRF)
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

PDFMathTranslate (pdf2zh) through 1.9.11 contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the server fetch arbitrary URLs via the Link input. The translate_file handler passes user URLs to download_with_limit without scheme or address validation, letting attackers reach internal services and cloud metadata endpoints and retrieve returned PDFs.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-10T15:16:58.547Z",
  "pubdate": "2026-10-10T15:16:58.547Z",
  "executiveSummary": "PDFMathTranslate (pdf2zh) versions up to 1.9.11 are susceptible to a Server-Side Request Forgery (SSRF) vulnerability. The vulnerability resides in the translate_file handler, which facilitates the fetching of external resources via a Link input parameter.\nThe flaw allows an unauthenticated remote attacker to coerce the server into performing arbitrary HTTP requests. By injecting malicious URLs, an attacker can bypass perimeter defenses to interact with internal network services or access sensitive cloud metadata endpoints (e.g., AWS/GCP/Azure instance metadata services).\nSuccessful exploitation results in the unauthorized retrieval of information, as the application returns the content of the fetched resources to the attacker. This poses a significant risk to internal infrastructure security, as the application effectively functions as an open proxy for scanning or data exfiltration from within the protected network perimeter.\nExploitation does not require authentication, making it a high-severity entry point for attackers to probe internal network topology or gain unauthorized access to cloud-native environmental secrets.",
  "technicalDetails": "The vulnerability is rooted in an improper implementation of input validation within the translate_file handler of the PDFMathTranslate application. Specifically, the function accepts a user-supplied Link parameter that is passed directly to the download_with_limit function without undergoing adequate sanitization, scheme validation, or address filtering.\nBecause the application fails to restrict the destination of the outgoing request, an attacker can supply URIs pointing to internal services (e.g., localhost, internal IP ranges) or protected cloud metadata services, which are typically only accessible from within the application's environment.\nThe attack flow proceeds as follows: An unauthenticated attacker submits a specifically crafted request to the translate_file endpoint, providing a targeted internal URI in the Link field. The backend server, acting on behalf of the attacker, initiates a network request to the specified destination. The download_with_limit function fetches the response from the targeted service. Finally, the application processes the retrieved content and returns the data (in the context of a PDF) back to the attacker, thereby exposing internal resources or sensitive configuration metadata.\nSince the application is vulnerable up to version 1.9.11, all deployments are at risk unless strict egress filtering is applied at the network level. The vulnerability allows for blind or out-of-band SSRF attacks, potentially leading to the extraction of sensitive environment variables, cloud IAM role credentials, or direct interaction with internal APIs that lack secondary authentication layers. Because the process returns the fetched file content, the attacker can verify successful exploitation by reviewing the returned PDF response generated from the arbitrary fetched content. This vulnerability leverages the server's identity to bypass firewall rules, effectively using the application as a bridge into otherwise inaccessible internal segments."
}
CVE-2026-108554: PDFMathTranslate SSRF Vulnerability (MEDIUM Severity, CVSS: 5.3) | Sceawere