PT-2026-38386 · Gotenberg · Gotenberg

R1Zzg0D

·

Published

2026-05-07

·

Updated

2026-06-25

·

CVE-2026-42596

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Gotenberg versions prior to 8.31.0
Description An unauthenticated attacker can bypass the default deny-lists used by the downloadFrom and webhook features. The issue occurs because the filtering logic uses case-sensitive regular expressions that only block lowercase http:// and https:// prefixes. Consequently, an attacker can use alternative textual representations of loopback or private addresses, such as IPv4-mapped IPv6 addresses (e.g., http://[::ffff:127.0.0.1]:...), to force the server to make outbound requests to internal-only targets. This allows for Server-Side Request Forgery (SSRF), potentially exposing internal HTTP services, cloud metadata endpoints, and local admin APIs.
Recommendations Update to version 8.31.0. As a temporary workaround, restrict access to the downloadFrom and webhook features to minimize the risk of exploitation.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42596
GHSA-4VMC-GM8V-M35H
GO-2026-5132

Affected Products

Gotenberg