PT-2026-28483 · Unknown · Stirling-Pdf

Crocogab

·

Publicado

2026-03-26

·

Atualizado

2026-03-26

·

CVE-2026-33438

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Stirling-PDF versions 2.1.5 through 2.5.1
Description Stirling-PDF is a locally hosted web application for PDF file operations. An authenticated user can trigger a Denial of Service (DoS) condition by submitting extreme values for the fontSize and widthSpacer parameters to the /api/v1/security/add-watermark endpoint. This can lead to resource exhaustion and server crashes.
Recommendations Versions prior to 2.5.2 should be updated to version 2.5.2 or later.

Exploit

Correção

Allocation of Resources Without Limits

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-33438
GHSA-3932-2RFQ-87XM

Produtos afetados

Stirling-Pdf