CVE-2026-34071

Source
https://cve.org/CVERecord?id=CVE-2026-34071
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-34071.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-34071
Aliases
  • GHSA-xmhg-fv84-jgfc
Published
2026-03-26T17:00:08.783Z
Modified
2026-07-15T01:49:05.331907003Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N CVSS Calculator
Summary
Stirling-PDF has Stored Cross Site Scripting (XSS) via EML-to-HTML Export
Details

Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. In version 2.7.3, the /api/v1/convert/eml/pdf endpoint with parameter downloadHtml=true returns unsanitized HTML from the email body with Content-Type: text/html. An attacker who sends a malicious email to a Stirling-PDF user can achieve JavaScript execution when that user exports the email using the "Download HTML intermediate file" feature. Version 2.8.0 fixes the issue.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/34xxx/CVE-2026-34071.json"
}
References

Affected packages

Git / github.com/stirling-tools/stirling-pdf

Affected ranges

Type
GIT
Repo
https://github.com/stirling-tools/stirling-pdf
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "= 2.7.3"
        },
        {
            "last_affected": "= 2.7.3"
        },
        {
            "introduced": "2.7.3"
        },
        {
            "last_affected": "2.7.3"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_STRING"
    ],
    "cpe": "cpe:2.3:a:stirling:stirling_pdf:2.7.3:*:*:*:*:*:*:*"
}

Affected versions

2.*
2.7.3
= 2.*
= 2.7.3
v2.*
v2.7.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-34071.json"