Spire.Doc is a professional Word .NET library specifically designed for developers to create, read, write, convert and print Word document files. Get free and professional technical support for Spire.Doc for .NET, Java, Android, C++, Python.

Mon Nov 24, 2025 9:11 am

Problem Description

When converting HTML and DOCX files to PDF using Spire.Officefor.NETStandard, the library performs unauthorized outbound HTTP requests to external URLs referenced inside the document (e.g., images loaded via <img src="…">).

This behavior introduces a critical security risk:
    - It enables Reflected Cross-Site-Scripting (XSS) / Injection attacks, aligned with OWASP TOP 10 – A03:2021 Injection.
    - It allows the application to act as an unintended proxy toward arbitrary hosts.
    - It may lead to data leakage, server IP exposure, or SSRF-like effects.

This occurs silently and automatically when loading the document—no explicit configuration triggers this behavior.

Environment

    - Application: ASP.NET Core 8
    - Library: Spire.Officefor.NETStandard

Conversion code:
Code: Select all
using FileStream fs = File.OpenRead("path");
using Document document = new();
document.LoadFromStream(fs, FileFormat.Auto);
document.SaveToFile("output.pdf", FileFormat.PDF);


Impact

    - Potential data exfiltration via external HTTP requests.
    - Possible injection attack vector, where malicious users craft HTML/DOCX documents containing harmful URLs.
    - Undocumented and uncontrollable behavior, making mitigation impossible on the application side.
    - Violation of internal security policies (unexpected outbound traffic).

Steps to Reproduce

    1. Create a minimal HTML file:
    Code: Select all
    <!html>
    <body>
      <img src="URL of an externally hosted image">
    </body>

    2. Convert the file to PDF using Spire:
    Code: Select all
    using FileStream fs = File.OpenRead("file.html");
    using Document document = new();
    document.LoadFromStream(fs, FileFormat.Auto);
    document.SaveToFile("output.pdf", Spire.Doc.FileFormat.PDF);

    3. Monitor the traffic using a tool such as Wireshark.
    4. Observe that the library performs a direct HTTP request to the external URL to retrieve the image.

Requested Actions
    1. Confirm whether this behavior is intended.
    2. Clarify if there is any flag / option / configuration to:
      - completely disable remote resource loading;
      - force usage of embedded or local resources only;
      - automatically replace remote resources with placeholders;
      - intercept or block outbound HTTP requests performed by the library.
    3. If no configuration is available:
      - provide a patch, hotfix, or updated version that removes or makes this behavior configurable.
    4. Share any information regarding:
      - known vulnerabilities,
      - recommended security best practices,
      - or safer alternatives.

Best regards,
Alessandro

alessandro.tl
 
Posts: 7
Joined: Wed Sep 10, 2025 7:31 am

Tue Nov 25, 2025 8:23 am

Hello,

Thank you for your feedback,
When the document has the information about "URL of an external..." , our product will indeed access and download the corresponding data to present the correct effect. To avoid this behavior, we can consider adding events and filtering through URL blacklists. Is this applicable to your actual situation? Looking forward to your feedback.

Sincerely,
Lisa
E-iceblue support team
User avatar

Lisa.Li
 
Posts: 1533
Joined: Wed Apr 25, 2018 3:20 am

Tue Nov 25, 2025 10:02 am

Thank you for your reply.

Yes, preventing external resource loading through an event-based mechanism would be acceptable for our scenario.
However, we have already attempted to subscribe to the HtmlUrlLoadEvent, and the event is never triggered during the document loading/conversion process.

Here is the code we used for testing:
Code: Select all
var document = new Document();
document.HtmlUrlLoadEvent += (sender, args) =>
{
    // This block is never reached
};

using var fs = File.OpenRead("file.html");
document.LoadFromStream(fs, FileFormat.Auto);
document.SaveToFile("output.pdf", FileFormat.PDF);


Even with this subscription, the library still performs direct HTTP requests for remote images, and the event handler is not invoked.

Thank you.

alessandro.tl
 
Posts: 7
Joined: Wed Sep 10, 2025 7:31 am

Wed Nov 26, 2025 1:26 am

Hello,

Thank you for your feedback,
Yes, this method has some adjustments in the current version, the event handler is not invoked. I have logged this issue with SPIREDOC-11696, our Dev team will further adjust and fix this issue. Once its' hotfix version is available, we will notify you as soon as possible. Thank you for your understanding.

Sincerely,
Lisa
E-iceblue support team
User avatar

Lisa.Li
 
Posts: 1533
Joined: Wed Apr 25, 2018 3:20 am

Thu Dec 11, 2025 10:12 am

Hello,

Thanks for your patience.
Glad to inform you that our latest version (Spire.Doc Pack(hot fix) Version:13.12.2) contains the fixes of SPIREDOC-11696. Please test it.

https://www.nuget.org/packages/Spire.Docfor.NETStandard/13.12.2
Code: Select all
{ Document doc = new Document();
doc.HtmlUrlLoadEvent += MyDownloadEvent;
doc.LoadFromFile(@"test.docx");
doc.SaveToFile(@"test.pdf"); }
private static void MyDownloadEvent(object sender, Spire.Doc.Document.HtmlUrlLoadEventArgs args)
{
// Create a blacklist list
List<string> blacklist = new List<string>

{ "http://google.com", }
;

using (WebClient webClient = new WebClient())
{
webClient.Credentials = CredentialCache.DefaultCredentials;
webClient.Headers.Set("user-agent", "Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:109.0) Gecko/20100101 Firefox/115.0");
//SystemDefault = 0,Ssl3 = 48,Tls = 192,Tls11 = 768,Tls12 = 3072,Tls13 = 12288
//System.Net.ServicePointManager.SecurityProtocol = (SecurityProtocolType)3072;

if (!IsWebsiteBlocked(args.Url, blacklist))

{ args.DataBytes = webClient.DownloadData(args.Url); }
}
}
private static bool IsWebsiteBlocked(string website,List<string> blacklist)
{
foreach (string blockedSite in blacklist)
{
if (website.StartsWith(blockedSite, StringComparison.OrdinalIgnoreCase))

{ return true; }
}
return false;
}

Sincerely,
Lisa
E-iceblue support team
User avatar

Lisa.Li
 
Posts: 1533
Joined: Wed Apr 25, 2018 3:20 am

Tue Apr 07, 2026 9:29 am

Hello,

I apologize for the delayed response. I can confirm that the proposed solution is working as expected.

Thank you.

alessandro.tl
 
Posts: 7
Joined: Wed Sep 10, 2025 7:31 am

Wed Apr 08, 2026 1:26 am

Hello,

Thank you for your feedback. If you have any other questions in the future, just feel free to contact us.

Sincerely,
Lisa
E-iceblue support team
User avatar

Lisa.Li
 
Posts: 1533
Joined: Wed Apr 25, 2018 3:20 am

Return to Spire.Doc

cron