PT-2026-97861 · Bentopdf · Bentopdf

CVE-2026-77581

·

Published

2026-09-24

·

Updated

2026-09-24

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions BentoPDF versions prior to 2.8.7
Description The certificate and timestamp CORS proxy in cloudflare/cors-proxy-worker.js uses the isPrivateOrReservedHost() function to validate a supplied hostname separately from the DNS resolution used by fetch(targetUrl). This discrepancy allows an attacker-controlled hostname to resolve to an internal or reserved destination after the validation process. A certificate-like path can satisfy ALLOWED PATH PATTERNS, and direct clients can forge the browser-oriented Origin header. In deployments where PROXY SECRET is not configured, the optional signature check is skipped. The proxy has a 10 MB response limit and can relay response bodies from reachable destinations. This issue impacts both official Worker deployments and self-hosted instances where the Worker execution environment has access to internal or reserved destinations.
Recommendations Update to version 2.8.7.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77581
GHSA-5XJF-RR5X-PCFJ

Affected Products

Bentopdf