Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.9.0, the /api/v1/pipeline/handleData endpoint in app/core/src/main/java/stirling/software/SPDF/controller/api/pipeline/PipelineProcessor.java injects the STIRLING-PDF-BACKEND-API-USER API key into pipeline subrequests, allowing an authenticated ROLE_USER to retrieve the key through /api/v1/user/get-api-key, impersonate the internal service account, bypass normal rate limits, and access internal endpoints including /api/v1/info/requests/all and /api/v1/info/load/all. This issue is fixed in version 2.9.0.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-200",
"CWE-522"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/57xxx/CVE-2026-57485.json"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "2.9.0"
}
],
"source": [
"AFFECTED_FIELD",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-57485.json"
[
{
"target": {
"function": "getApiKeyForUser",
"file": "app/core/src/main/java/stirling/software/SPDF/controller/api/pipeline/PipelineProcessor.java"
},
"deprecated": false,
"source": "https://github.com/stirling-tools/stirling-pdf/commit/de9625942bbc329fdefcfde161476a633a3b3213",
"id": "CVE-2026-57485-3ba1ebec",
"signature_version": "v1",
"digest": {
"length": 137.0,
"function_hash": "234297141440362152734560238802621289436"
},
"signature_type": "Function"
},
{
"target": {
"file": "app/core/src/main/java/stirling/software/SPDF/controller/api/pipeline/PipelineProcessor.java"
},
"deprecated": false,
"source": "https://github.com/stirling-tools/stirling-pdf/commit/de9625942bbc329fdefcfde161476a633a3b3213",
"id": "CVE-2026-57485-81a5d31c",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"235228173463927565018025764600140215892",
"166979776421328109385959753842389790323",
"40241952217658033835296506824672325648",
"309737468468861894166149215746311630781",
"290621123642718380868952501183331398980",
"168084004279713636886079555991632233204",
"137657571509118400244188449780515338817",
"57712175389913542339634824976723442918",
"180818081980839534940866047053884706443",
"319731776182995543011073870918626824076",
"25698744105070796851003242137919031074",
"336535835153978586810286964839961495372",
"74937386612274205755028970354163412577",
"306287065515610712013620518522149537784"
]
},
"signature_type": "Line"
},
{
"target": {
"function": "sendWebRequest",
"file": "app/core/src/main/java/stirling/software/SPDF/controller/api/pipeline/PipelineProcessor.java"
},
"deprecated": false,
"source": "https://github.com/stirling-tools/stirling-pdf/commit/de9625942bbc329fdefcfde161476a633a3b3213",
"id": "CVE-2026-57485-b700e1e4",
"signature_version": "v1",
"digest": {
"length": 818.0,
"function_hash": "28986536665470436617747361859313948792"
},
"signature_type": "Function"
},
{
"target": {
"file": "app/proprietary/src/main/java/stirling/software/proprietary/security/service/UserService.java"
},
"deprecated": false,
"source": "https://github.com/stirling-tools/stirling-pdf/commit/de9625942bbc329fdefcfde161476a633a3b3213",
"id": "CVE-2026-57485-ba286da5",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"18759565327884163562626176467182442558",
"51887953726811454205015443415573316699",
"38348652142423839889374313549400838503"
]
},
"signature_type": "Line"
},
{
"target": {
"function": "sendWebRequestDoesNotForceContentType",
"file": "app/core/src/test/java/stirling/software/SPDF/controller/api/pipeline/PipelineProcessorTest.java"
},
"deprecated": false,
"source": "https://github.com/stirling-tools/stirling-pdf/commit/de9625942bbc329fdefcfde161476a633a3b3213",
"id": "CVE-2026-57485-c26f10c7",
"signature_version": "v1",
"digest": {
"length": 1987.0,
"function_hash": "222188545631147153831244176071076277703"
},
"signature_type": "Function"
},
{
"target": {
"file": "app/core/src/test/java/stirling/software/SPDF/controller/api/pipeline/PipelineProcessorTest.java"
},
"deprecated": false,
"source": "https://github.com/stirling-tools/stirling-pdf/commit/de9625942bbc329fdefcfde161476a633a3b3213",
"id": "CVE-2026-57485-c69bb1ee",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"262014355046864183798361470163351279444",
"317334660409149979663901620919646432992",
"233461589336630975834898268570214247858",
"264498932870273196538825673909179383141"
]
},
"signature_type": "Line"
},
{
"target": {
"file": "app/common/src/main/java/stirling/software/common/service/UserServiceInterface.java"
},
"deprecated": false,
"source": "https://github.com/stirling-tools/stirling-pdf/commit/de9625942bbc329fdefcfde161476a633a3b3213",
"id": "CVE-2026-57485-d4542d3b",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"203009044399226979668151425642853155369",
"218816527615080155421802453970156092025",
"202391872871398088187649692559683066357"
]
},
"signature_type": "Line"
}
]
"2026-08-20T10:17:19Z"