Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 17 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.9.0, the /api/v1/pipeline/handleData endpoint in app/core/src/main/java/stirling/software/SPDF/controller/api/pipeline/PipelineProcessor.java injects the STIRLING-PDF-BACKEND-API-USER API key into pipeline subrequests, allowing an authenticated ROLE_USER to retrieve the key through /api/v1/user/get-api-key, impersonate the internal service account, bypass normal rate limits, and access internal endpoints including /api/v1/info/requests/all and /api/v1/info/load/all. This issue is fixed in version 2.9.0. | |
| Title | Stirling-PDF: Internal Service Account API Key Disclosure via Pipeline Endpoint | |
| Weaknesses | CWE-200 CWE-522 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-17T19:31:30.833Z
Reserved: 2026-06-24T14:53:40.111Z
Link: CVE-2026-57485
No data.
Status : Received
Published: 2026-08-17T20:16:44.587
Modified: 2026-08-17T20:16:44.587
Link: CVE-2026-57485
No data.
OpenCVE Enrichment
Updated: 2026-08-17T20:30:17Z