CVE-2026-26801 is a Server-Side Request Forgery vulnerability affecting pdfmake versions 0.3.0-beta.2 through 0.3.5. The issue is in the src/URLResolver.js component, which can be abused by a remote attacker to cause the server-side application using pdfmake to fetch attacker-influenced URLs. In server-side deployments, this can expose internal or otherwise restricted network resources and sensitive information reachable from the host running pdfmake. The issue was addressed in pdfmake 0.3.6.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a working JavaScript PoC for an SSRF vulnerability in pdfmake, identified as CVE-2026-26801, affecting versions >= 0.3.0-beta.2 through <= 0.3.5 and fixed in 0.3.6. It is not part of a larger exploit framework. The repo contains a complete local lab: a deliberately vulnerable Express server (vulnerable-server.js), a mock cloud metadata service (mock-metadata-server.js), a blind SSRF attack client (attack.js), a full-read/data-exfiltration attack client (attack-exfiltration.js), and a minimal trigger test (test-minimal.js). Core exploit capability: the attacker submits a crafted pdfmake docDefinition to the vulnerable server’s POST /api/generate-pdf endpoint. Because pdfmake resolves URLs in images, attachments, and files without validation, the server performs outbound fetches to attacker-chosen or internal targets. The blind SSRF path demonstrates request triggering against metadata-style endpoints and internal APIs, including support for custom headers to simulate auth bypass against trusted internal services. The stronger exfiltration path abuses attachments plus files so fetched remote content is first stored in pdfmake’s virtual filesystem and then embedded into the returned PDF as an attachment, allowing the attacker to recover the response body from the generated PDF. Repository structure and purpose: README.md documents the vulnerability, affected versions, setup, and expected results. vulnerable-server.js is the main vulnerable target application exposing /api/generate-pdf and /health. mock-metadata-server.js simulates AWS IMDS-style endpoints on port 8888 and returns fake credentials and metadata values. attack.js sends several malicious docDefinitions to prove blind SSRF and header injection. attack-exfiltration.js automates the full-read SSRF flow, saves exfiltrated.pdf, and optionally extracts metadata.json using pdfdetach. test-minimal.js is a stripped-down confirmation that pdfmake.createPdf triggers URL resolution. package.json wires the demo together with npm scripts. Overall, this is a legitimate operational PoC demonstrating both SSRF and response exfiltration against server-side pdfmake usage, with clearly identifiable network targets and a realistic attack chain.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.