CVE-2026-42591

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the LibreOffice conversion endpoint (/forms/libreoffice/convert) passes uploaded documents directly to LibreOffice without inspecting their content. LibreOffice then fetches any embedded external URLs on its own, completely bypassing the SSRF filters. This vulnerability is fixed in 8.32.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:thecodingmachine:gotenberg:*:*:*:*:*:*:*:*

History

18 May 2026, 13:02

Type Values Removed Values Added
First Time Thecodingmachine gotenberg
Thecodingmachine
CPE cpe:2.3:a:thecodingmachine:gotenberg:*:*:*:*:*:*:*:*
References () https://github.com/gotenberg/gotenberg/security/advisories/GHSA-rm4c-xj6x-49mw - () https://github.com/gotenberg/gotenberg/security/advisories/GHSA-rm4c-xj6x-49mw - Exploit, Vendor Advisory

14 May 2026, 18:16

Type Values Removed Values Added
References () https://github.com/gotenberg/gotenberg/security/advisories/GHSA-rm4c-xj6x-49mw - () https://github.com/gotenberg/gotenberg/security/advisories/GHSA-rm4c-xj6x-49mw -

14 May 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-14 16:16

Updated : 2026-05-18 13:02


NVD link : CVE-2026-42591

Mitre link : CVE-2026-42591

CVE.ORG link : CVE-2026-42591


JSON object : View

Products Affected

thecodingmachine

  • gotenberg
CWE
CWE-918

Server-Side Request Forgery (SSRF)