6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Description
Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. Versions starting in 2.1.5 and prior to 2.5.2 have Denial of Service (DoS) vulnerability in the Stirling-PDF watermark functionality (`/api/v1/security/add-watermark` endpoint). The vulnerability allows authenticated users to cause resource exhaustion and server crashes by providing extreme values for the `fontSize` and `widthSpacer` parameters. Version 2.5.2 patches the issue.
Basic Information
ID
CVE-2026-33438
Source
GitHub_M
Published
Mar 26, 2026 at 16:58
Modified
Mar 26, 2026 at 17:34
Affected Product
Vendor
Stirling-Tools
Product
Stirling-PDF
Version
>= 2.1.5, < 2.5.2
Affected Versions
Stirling-Tools Stirling-PDF >= 2.1.5, < 2.5.2