Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-34071

22
FAUCET Score

CVE-2026-34071 identifies a Cross-Site Scripting (XSS) vulnerability in Stirling-PDF version 2.7.3, specifically within the /api/v1/convert/eml/pdf endpoint when exporting emails with the "Download HTML intermediate file" option. This medium-severity vulnerability (CVSS 6.1) allows an unauthenticated attacker to achieve JavaScript execution in a user's browser by sending a malicious email, requiring user interaction to trigger the exploit. The potential impact includes low confidentiality and integrity, though its EPSS score of 0.000360000 indicates a very low likelihood of exploitation. There is currently no evidence of active exploitation, nor is public exploit code or significant community discussion available for this flaw, which is resolved in Stirling-PDF version 2.8.0.

Impacted Technologies

VendorProductVersion(s)CPE
2.7.3CPE matchmatch criteria
cpe:2.3:a:stirling:stirling_pdf:2.7.3:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.4MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
2.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.26%
Probability of exploitation in next 30 days
EPSS Percentile
17.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0026 is in the 18th percentile among its peer group of 26,219 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

github_advisoryvendor investigatingvia nvd_reference
View patch

References

github.com / Stirling-Tools/Stirling-PDF/security/advisories/GHSA-xmhg-fv84-jgfc
ExploitVendor Advisory