CVE-2026-86273 | projeto-siga up to 11.1.1 HTML-to-PDF Endpoint ExUtilController.java DownloadExterno.getUrl html server-side request forgery (Issue 2492)
A vulnerability classified as critical has been found in projeto-siga siga up to 11.1.1. Affected by this issue is the function DownloadExterno.getUrl of the file sigaex/src/main/java/br/gov/jfrj/siga/vraptor/ExUtilController.java of the component HTML-to-PDF Endpoint. This manipulation of the argument html causes server-side request forgery.
This vulnerability appears as CVE-2026-86273. The attack may be initiated remotely. In addition, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More