Concurrency Flaw in Gotenberg API Allows Denial of Service
CVE-2026-45742

7.5HIGH

Key Information:

Vendor

Gotenberg

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-45742?

A concurrency issue in the Gotenberg API allows unauthenticated remote attackers to exploit shared data structures during file downloads. The errgroup.Go goroutines lead to concurrent writes to the shared maps and slices, which can trigger data races. Consequently, a crafted multipart request with multiple download entries can cause a fatal runtime error, resulting in denial of service. This vulnerability impacts versions 8.10.0 through 8.33.0 and is corrected in version 8.33.0.

Affected Version(s)

gotenberg >= 8.10.0, < 8.33.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.