Gotenberg < 8.31.0 - Server-Side Request Forgery
CVE-2026-42596
Verified
Description
Gotenberg before 8.31.0 is vulnerable to server-side request forgery (SSRF) due to insufficient validation of URLs in the downloadFrom API. An unauthenticated attacker can exploit the flaw by providing specially crafted IPv4-mapped IPv6 addresses (such as http://[::ffff:127.0.0.1]) that bypass the deny-list and allow access to internal resources. Fixed versions properly recognize these addresses and prevent such requests.
Severity
Critical
CVSS Score
9.8
Exploit Probability
2%
Published Date
August 30, 2026
Template Author
str4k3r
CVE-2026-42596.yaml
9.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-42596
CWE ID:
cwe-918