Regex-Based Bypass Vulnerability in Gotenberg PDF API by Gotenberg
CVE-2026-42596

9.4CRITICAL

Key Information:

Vendor

Gotenberg

Status
Vendor
CVE Published:
14 May 2026

What is CVE-2026-42596?

CVE-2026-42596 is a vulnerability found in the Gotenberg PDF API, a Docker-powered stateless API designed for handling PDF file operations. This vulnerability arises from a flaw in the regex-based deny-lists implemented in Gotenberg's features, specifically the downloadFrom and webhook functionalities. Prior to version 8.31.0, the filters that were supposed to restrict unwanted access could be bypassed by unauthenticated attackers. This allows potential intruders to exploit the system by sending specially crafted URLs that access loopback or private HTTP services, which are meant to be blocked. As a result, an external attacker can force the server to make requests to internal resources, breaching established security boundaries and risking sensitive data exposure.

Potential impact of CVE-2026-42596

  1. Unauthorized Access to Internal Services: The vulnerability allows attackers to bypass security measures, enabling them to connect to internal-only services, which may expose sensitive data or functionality typically protected from external access.

  2. Data Breaches: By gaining access to sensitive internal services, attackers could potentially exfiltrate confidential information, leading to data breaches that could have severe legal and reputational ramifications for affected organizations.

  3. Increased Attack Surface: The ability of an unauthorized party to initiate outbound requests to internal networks widens the attack surface considerably, creating new vectors for exploitation and further attacks within the organization’s infrastructure.

Affected Version(s)

gotenberg < 8.31.0

References

CVSS V3.1

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.