Skip to content
vaultocean
Field
highSSRF
6 min read2026-06-11

Blind SSRF reaching cloud metadata through a PDF renderer

AN

anon

security researcher · vault ocean

A server-side HTML-to-PDF feature followed redirects to 169.254.169.254 and embedded IAM creds in the output.

The renderer fetched remote resources without an allow-list and followed redirects. A crafted document pointed at the link-local metadata endpoint, and the temporary IAM credentials landed in the rendered PDF. Fix: block link-local/metadata ranges, disable redirects, require IMDSv2.

You read it — record it

sign in to record this and keep your streak alive

Reading earns +25ƒ and keeps your streak alive.

Discussion · 0

Loading…

Sign in to leave a comment.

AN

Written by

anon

Security researcher · Vault Ocean contributor