Junglewise Threat Intelligence

CVE-2026-57485: Stirling-PDF API key exposure in pipeline requests

CVE-2026-57485 · Severity: high · CVSS 8.5 · Published 2026-08-17

Technologies: Stirling-Tools Stirling Pdf.

Executive brief

Stirling-PDF is a web application that handles PDF document processing and operations. Prior to version 2.9.0, a flaw allows authenticated users to retrieve the internal backend API key, impersonate the service account, bypass rate limiting, and access sensitive internal endpoints that reveal request metrics and system load information. This could enable attackers to gain unauthorized visibility into system operations and bypass security controls.

Technical details

The vulnerability exists in the /api/v1/pipeline/handleData endpoint (PipelineProcessor.java), which injects the STIRLING-PDF-BACKEND-API-USER API key into subrequests made during pipeline processing. An authenticated user with ROLE_USER can then retrieve the exposed key via the /api/v1/user/get-api-key endpoint and use it to impersonate the internal service account. This allows bypassing rate limits and accessing protected internal endpoints including /api/v1/info/requests/all and /api/v1/info/load/all. The attack requires prior authentication but operates over the network with no additional user interaction needed. The fix was released in version 2.9.0.

Affected products

  • Stirling-Tools Stirling-PDF prior to 2.9.0

Timeline

  • 2026-08-17: disclosed
  • 2026-04-02: patched: Version 2.9.0 released

References