Content injected to PDF rendering contexts could, in many places, include HTML content including <img> tags. If the src
attribute of these images pointed to an URL, the PDF rendering engine
would download the image from that place and display it, thereby leaking
information about the rendering server and possibly creating an SSRF
vector in the local network.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://pretix.eu/about/en/blog/20260625-release-2026-5-2/ |
|
History
Thu, 25 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 25 Jun 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Image URL Retrieval via PDF Content Injection Leaks Server Info and Enables SSRF |
Thu, 25 Jun 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Content injected to PDF rendering contexts could, in many places, include HTML content including <img> tags. If the src attribute of these images pointed to an URL, the PDF rendering engine would download the image from that place and display it, thereby leaking information about the rendering server and possibly creating an SSRF vector in the local network. | |
| Weaknesses | CWE-80 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: rami.io
Published:
Updated: 2026-06-25T15:10:48.584Z
Reserved: 2026-06-24T15:59:32.628Z
Link: CVE-2026-57535
Updated: 2026-06-25T15:10:44.829Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-25T15:45:05Z