CVE-2026-42591

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the LibreOffice conversion endpoint (/forms/libreoffice/convert) passes uploaded documents directly to LibreOffice without inspecting their content. LibreOffice then fetches any embedded external URLs on its own, completely bypassing the SSRF filters. This vulnerability is fixed in 8.32.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:thecodingmachine:gotenberg:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-14 16:16

Updated : 2026-06-17 10:48


NVD link : CVE-2026-42591

Mitre link : CVE-2026-42591

CVE.ORG link : CVE-2026-42591


JSON object : View

Products Affected

thecodingmachine

  • gotenberg
CWE
CWE-918

Server-Side Request Forgery (SSRF)