Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-77581— BentoPDF: SSRF in cors-proxy-worker.js via DNS-based hostname allowlist bypass

Quick assessment

Affected
alam00000 bentopdf
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

BentoPDF 是一个可自托管的客户端 PDF 工具包。在版本 2.8.6 及更早版本中,cloudflare/cors-proxy-worker.js 中用于处理证书和时间戳的 CORS 代理使用 isPrivateOrReservedHost() 函数对提供的 hostname 进行单独验证,而该验证与 fetch(targetUrl) 实际使用的 DNS 解析过程相互独立。攻击者可以利用这一缺陷,在验证通过后,使一个由其控制的 hostname 解析到一个内部或保留地址。此外,类似证书路径的内容可以满足 A

CVSS 8.6 · High EPSS 0.27% · P17

Affected Version Matrix 1

VendorProduct Version RangeStatus
alam00000 bentopdf < 2.8.7 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-77581

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
BentoPDF: SSRF in cors-proxy-worker.js via DNS-based hostname allowlist bypass
Source: CVE Program / CVE List V5
Vulnerability Description
BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6 and earlier, the certificate and timestamp CORS proxy in cloudflare/cors-proxy-worker.js uses isPrivateOrReservedHost() to validate a supplied hostname separately from the DNS resolution used by fetch(targetUrl), allowing an attacker-controlled hostname to resolve to an internal or reserved destination after validation. A certificate-like path can satisfy ALLOWED_PATH_PATTERNS, and direct clients can forge the browser-oriented Origin header. Deployments without PROXY_SECRET skip the optional signature check, while the signature is an anti-abuse measure rather than a destination-security boundary. The proxy has a 10 MB response limit and can relay response bodies from reachable destinations. The advisory identifies both the official Worker deployment and self-hosted instances as impacted where the Worker execution environment can reach internal or reserved destinations. This vulnerability is fixed in 2.8.7.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
服务端请求伪造(SSRF)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
alam00000 bentopdf < 2.8.7 -

II. Public POCs for CVE-2026-77581

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-77581

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-77581 (2)

Vendor Advisories for CVE-2026-77581 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-77581

No comments yet


Leave a comment