PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108554 PDFMathTranslate CVE debrief

CVE-2026-108554 is a server-side request forgery vulnerability in PDFMathTranslate (pdf2zh) through 1.9.11. The vulnerability allows unauthenticated attackers to make the server fetch arbitrary URLs via the Link input. The translate_file handler passes user URLs to download_with_limit without scheme or address validation, letting attackers reach internal services and cloud metadata endpoints and retrieve returned PDFs.

Vendor
PDFMathTranslate
Product
Unknown
CVSS
MEDIUM 6.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

Defenders responsible for PDFMathTranslate installations, especially those accessible to untrusted networks, should assess exposure and prioritize verification and potential mitigations.

Why it matters

CVE-2026-108554 is a server-side request forgery vulnerability in PDFMathTranslate (pdf2zh) through 1.9.11 that allows unauthenticated attackers to fetch arbitrary URLs, potentially leading to unauthorized access to internal services and cloud metadata endpoints.

  • Potential unauthorized access to internal services and cloud metadata endpoints.
  • Possible retrieval of sensitive information from returned PDFs.
  • Need for verification of PDFMathTranslate installations and exposure.
  • Prioritization of restricting access to the translate_file handler.

Technical summary

The translate_file handler in PDFMathTranslate (pdf2zh) through 1.9.11 passes user URLs to download_with_limit without scheme or address validation, allowing attackers to reach internal services and cloud metadata endpoints. This vulnerability allows unauthenticated attackers to make the server fetch arbitrary URLs via the Link input, potentially leading to unauthorized access to internal services and cloud metadata endpoints and retrieval of returned PDFs. Defenders should prioritize verifying exposure of PDFMathTranslate installations, especially those accessible to untrusted networks, and assess the feasibility of restricting access to the translate_file handler.

Defensive priority

Defenders should prioritize verifying exposure of PDFMathTranslate installations, especially those accessible to untrusted networks, and assess the feasibility of restricting access to the translate_file handler.

Recommended defensive actions

  • Verify exposure of PDFMathTranslate installations, especially those accessible to untrusted networks.
  • Assess the feasibility of restricting access to the translate_file handler.
  • Monitor for suspicious activity related to the translate_file handler.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but information on affected versions, exploitation, and remediation is limited. Further verification is required to determine the scope of exposure and necessary mitigations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108554 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108554

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108554 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108554

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.