A server-side request forgery (SSRF) vulnerability has been identified in projeto-siga siga up to version 11.1.1. The vulnerability exists in the function DownloadExterno.getUrl within the file ExUtilController.java, part of the HTML-to-PDF Endpoint component. An attacker can manipulate the 'html' argument to trigger SSRF attacks remotely. A public exploit is already available, increasing the risk of active exploitation. The project maintainers were notified via an issue report but have not yet responded or released a patch. The vulnerability is remotely exploitable and poses a significant risk to deployments of the affected software.