CVE-2025-55150: Stirling-PDF SSRF vulnerability on /api/v1/convert/html/pdf
Stirling-PDF is a locally hosted web application that performs various operations on PDF files. Prior to version 1.1.0, when using the /api/v1/convert/html/pdf endpoint to convert HTML to PDF, the backend calls a third-party tool to process it and includes a sanitizer for security sanitization which can be bypassed and result in SSRF. This issue has been patched in version 1.1.0.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55150?
CVE-2025-55150 is classified as a moderate severity vulnerability.
How do I fix CVE-2025-55150?
To fix CVE-2025-55150, update Stirling-PDF to version 1.1.0 or later.
What versions of Stirling-PDF are affected by CVE-2025-55150?
CVE-2025-55150 affects Stirling-PDF versions prior to 1.1.0.
What is the impact of CVE-2025-55150?
CVE-2025-55150 may lead to security sanitization failures when converting HTML to PDF.
Is it safe to use Stirling-PDF before updating for CVE-2025-55150?
Using affected versions of Stirling-PDF before updating for CVE-2025-55150 may expose your application to potential security risks.