Denial of Service Vulnerability in Stirling-PDF by Stirling Tools
CVE-2026-33438

6.5MEDIUM

Key Information:

Vendor
CVE Published:
26 March 2026

What is CVE-2026-33438?

The Stirling-PDF application, designed for PDF file operations, has a vulnerability in the watermark functionality that can be exploited by authenticated users. By sending extreme values for the parameters fontSize and widthSpacer, an attacker can cause excessive resource consumption, leading to server crashes. This issue has been addressed in version 2.5.2, highlighting the importance of prompt updates to secure systems against potential misuse.

Affected Version(s)

Stirling-PDF >= 2.1.5, < 2.5.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.