216.73.216.197

CVE-2026-42591

· Published 14/05/2026 16:16 · Modified 14/05/2026 18:16

Labels: CVE-2026-42591 2026-05-14CVE-2026-42591CWE-918[email protected]

Essential information

Published
14/05/2026 16:16
Modified
14/05/2026 18:16
Author
Creator
CVSS
8.2 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CVSS metrics

Description

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the LibreOffice conversion endpoint (/forms/libreoffice/convert) passes uploaded documents directly to LibreOffice without inspecting their content. LibreOffice then fetches any embedded external URLs on its own, completely bypassing the SSRF filters. This vulnerability is fixed in 8.32.0.

NVD status

Status
Undergoing Analysis — CVE is currently being analyzed by NVD staff, this process results in association of reference link tags, CVSS scores, CWE association, and CPE applicability statements.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
gotenberg / gotenberg cpe:2.3:a:gotenberg:gotenberg:*:*:*:*:*:*:*:*
libreoffice / libreoffice cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:*

References