Junglewise Threat Intelligence

CVE-2026-77581: BentoPDF CORS proxy DNS rebinding in Cloudflare Worker

CVE-2026-77581 · Severity: high · CVSS 8.6 · Published 2026-09-24

Executive brief

BentoPDF is a self-hosted client-side PDF toolkit that includes a CORS proxy worker. In versions 2.8.6 and earlier, the proxy improperly validates hostnames, allowing an attacker to bypass security checks through DNS rebinding and access internal or reserved network destinations. An attacker can retrieve up to 10 MB of data from those internal systems, potentially exposing sensitive information or enabling further attacks.

Technical details

The vulnerability is a DNS rebinding flaw in the cors-proxy-worker.js CORS proxy: hostname validation using isPrivateOrReservedHost() happens before DNS resolution, but the actual fetch() may resolve to a different IP address controlled by the attacker, reaching internal/reserved destinations. The proxy path validation can be satisfied with certificate-like paths, and unsigned requests are accepted when PROXY_SECRET is not configured. An attacker with network-level or DNS control can forge requests with arbitrary Origin headers to exfiltrate response bodies up to 10 MB from reachable internal services.

Affected products

  • alam00000 BentoPDF 2.8.6 and earlier

Timeline

  • 2026-09-24: disclosed
  • 2026-07-14: patched: Fixed in version 2.8.7

References