CVE-2026-108554: Pdfmathtranslate

Medium severity, CVSS 5.3.

PDFMathTranslate (pdf2zh) through 1.9.11 contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the server fetch arbitrary URLs via the Link input. The translate_file handler passes user URLs to download_with_limit without scheme or address validation, letting attackers reach internal services and cloud metadata endpoints and retrieve returned PDFs.

Affected products

Published 2026-10-10. Last modified 2026-10-10.