PatchSiren cyber security CVE debrief
CVE-2026-108554 PDFMathTranslate CVE debrief
CVE-2026-108554 is a server-side request forgery vulnerability in PDFMathTranslate (pdf2zh) through 1.9.11. The vulnerability allows unauthenticated attackers to make the server fetch arbitrary URLs via the Link input. The translate_file handler passes user URLs to download_with_limit without scheme or address validation, letting attackers reach internal services and cloud metadata endpoints and retrieve returned PDFs.
- Vendor
- PDFMathTranslate
- Product
- Unknown
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Defenders responsible for PDFMathTranslate installations, especially those accessible to untrusted networks, should assess exposure and prioritize verification and potential mitigations.
Why it matters
CVE-2026-108554 is a server-side request forgery vulnerability in PDFMathTranslate (pdf2zh) through 1.9.11 that allows unauthenticated attackers to fetch arbitrary URLs, potentially leading to unauthorized access to internal services and cloud metadata endpoints.
- Potential unauthorized access to internal services and cloud metadata endpoints.
- Possible retrieval of sensitive information from returned PDFs.
- Need for verification of PDFMathTranslate installations and exposure.
- Prioritization of restricting access to the translate_file handler.
Technical summary
The translate_file handler in PDFMathTranslate (pdf2zh) through 1.9.11 passes user URLs to download_with_limit without scheme or address validation, allowing attackers to reach internal services and cloud metadata endpoints. This vulnerability allows unauthenticated attackers to make the server fetch arbitrary URLs via the Link input, potentially leading to unauthorized access to internal services and cloud metadata endpoints and retrieval of returned PDFs. Defenders should prioritize verifying exposure of PDFMathTranslate installations, especially those accessible to untrusted networks, and assess the feasibility of restricting access to the translate_file handler.
Defensive priority
Defenders should prioritize verifying exposure of PDFMathTranslate installations, especially those accessible to untrusted networks, and assess the feasibility of restricting access to the translate_file handler.
Recommended defensive actions
- Verify exposure of PDFMathTranslate installations, especially those accessible to untrusted networks.
- Assess the feasibility of restricting access to the translate_file handler.
- Monitor for suspicious activity related to the translate_file handler.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but information on affected versions, exploitation, and remediation is limited. Further verification is required to determine the scope of exposure and necessary mitigations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108554 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108554
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108554 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108554
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/PDFMathTranslate/PDFMathTranslate
-
Source reference
Unverified legacy reference
URL: https://github.com/PDFMathTranslate/PDFMathTranslate/blob/0f0618d3303d064d97e7adb77557b21236c6cee0/pdf2zh/gui.py
-
Source reference
Unverified legacy reference
URL: https://github.com/PDFMathTranslate/PDFMathTranslate/issues/1188
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/pdfmathtranslate-through-1.9.11-ssrf-via-gradio-web-gui-link-input
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.