[Security 9.8 CRITICAL] CVE-2022-35583 - wkhtmlTOpdf 0.12.6 is vulnerable to SSRF (Server-side request forgery) · Issue #5249 · wkhtmltopdf/wkhtmltopdf
See https://nvd.nist.gov/vuln/detail/CVE-2022-35583 and https://cyber-guy.gitbook.io/cyber-guys-blog/blogs/initial-access-via-pdf-file-silently