/Vulnerability Library

Gotenberg < 8.31.0 - Server-Side Request Forgery

CVE-2026-42596
Verified

Description

Gotenberg before 8.31.0 is vulnerable to server-side request forgery (SSRF) due to insufficient validation of URLs in the downloadFrom API. An unauthenticated attacker can exploit the flaw by providing specially crafted IPv4-mapped IPv6 addresses (such as http://[::ffff:127.0.0.1]) that bypass the deny-list and allow access to internal resources. Fixed versions properly recognize these addresses and prevent such requests.

Severity

Critical

CVSS Score

9.8

Exploit Probability

2%

Published Date

August 30, 2026

Template Author

str4k3r

CVE-2026-42596.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-42596
CWE ID:
cwe-918

References

https://github.com/gotenberg/gotenberg/security/advisories/GHSA-4vmc-gm8v-m35hhttps://nvd.nist.gov/vuln/detail/CVE-2026-42596