Executive brief
Projeto SIGA is a Brazilian government document management system used for managing official communications and workflows. An unauthenticated attacker can exploit a flaw in the HTML-to-PDF conversion feature to make the SIGA server fetch arbitrary URLs, potentially exposing internal services, accessing private resources, or conducting network reconnaissance against systems only reachable from the server.
Technical details
The vulnerability is a server-side request forgery (SSRF) in the HTML-to-PDF endpoint at POST /sigaex/public/app/util/html-pdf, implemented in the ExUtilController.getUrl() method. The endpoint accepts unauthenticated requests and passes user-controlled HTML parameters to a Flying Saucer renderer, which fetches embedded resource URLs (such as image sources) without destination allowlisting or validation. The underlying SigaHTTP.fetch() function lacks timeout and access restrictions, allowing attackers to reach loopback addresses, private networks, and link-local ranges. The vulnerability affects versions 5.4.10 through 11.1.1; no patch is currently available.
Affected products
- Projeto SIGA SIGA 5.4.10 through 11.1.1
Timeline
- 2026-07-25: disclosed: Issue opened on GitHub
- 2026-09-07: advisory: CVE-2026-86273 published
- 2026-09-07: other: Public exploit code available