Beveiligingsadvies

CVE-2026-55229

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-07-10 20:35:12
Laatst bijgewerkt 2026-07-13 16:19:22
Toegewezen door GitHub_M
CVSS-score 7.5
Status PUBLISHED

Beschrijving

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.34.0, Gotenberg's /forms/libreoffice/convert endpoint allows a specially crafted document to cause LibreOffice to automatically retrieve external HTTP(S) resources and local file resources during document conversion, enabling blind SSRF and limited local file disclosure via linked image resource loading. This issue is fixed in version 8.34.0.