Beveiligingsadvies

CVE-2026-42591

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-05-14 15:20:43
Laatst bijgewerkt 2026-05-14 18:07:57
Toegewezen door GitHub_M
CVSS-score 8.2
Status PUBLISHED

Beschrijving

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the LibreOffice conversion endpoint (/forms/libreoffice/convert) passes uploaded documents directly to LibreOffice without inspecting their content. LibreOffice then fetches any embedded external URLs on its own, completely bypassing the SSRF filters. This vulnerability is fixed in 8.32.0.