PT-2026-97861 · Bentopdf · Bentopdf
CVE-2026-77581
·
Published
2026-09-24
·
Updated
2026-09-24
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
BentoPDF versions prior to 2.8.7
Description
The certificate and timestamp CORS proxy in
cloudflare/cors-proxy-worker.js uses the isPrivateOrReservedHost() function to validate a supplied hostname separately from the DNS resolution used by fetch(targetUrl). This discrepancy allows an attacker-controlled hostname to resolve to an internal or reserved destination after the validation process. A certificate-like path can satisfy ALLOWED PATH PATTERNS, and direct clients can forge the browser-oriented Origin header. In deployments where PROXY SECRET is not configured, the optional signature check is skipped. The proxy has a 10 MB response limit and can relay response bodies from reachable destinations. This issue impacts both official Worker deployments and self-hosted instances where the Worker execution environment has access to internal or reserved destinations.Recommendations
Update to version 2.8.7.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bentopdf