LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-42596

CVE-2026-42596 - Vulnerability Analysis

CriticalCVSS: 9.4

Last Updated: May 14, 2026

Gotenberg - Server Side Request Forgery

Published: May 14, 2026Updated: May 14, 2026Remote Exploitable

Overview

Gotenberg < 8.31.0 contains a server-side request forgery caused by case-sensitive regex filtering in downloadFrom and webhook features, letting unauthenticated attackers access internal HTTP services, exploit requires crafted URLs.

Severity & Score

Severity: Critical
CVSS Score: 9.4
EPSS Score: 0.0%(Probability of exploitation in next 30 days)

Impact

Unauthenticated attackers can make the server send requests to internal-only services, potentially exposing sensitive internal resources.

Mitigation

Upgrade to version 8.31.0 or later.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
May 14, 2026

šŸ”“ CVE-2026-42596 - Critical (9.4) Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, the default deny-lists used by Gotenberg's downloadFrom feature and webhook feature are bypassable. Because the filter is regex-based and case-sensitive, an unauthenticate... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-42596/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
May 14, 2026

šŸ”“ CVE-2026-42596 - Critical (9.4) Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, the default deny-lists used by Gotenberg's downloadFrom feature and webhook feature are bypassable. Because the filter is regex-based and case-sensitive, an unauthenticate... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-42596/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-42596
Severity
Critical
CVSS Score
9.4
Type
server_side_request_forgery
Status
unconfirmed
EPSS
0.0%
Social Posts
2

CWE

  • CWE-918

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

EPSS Score

0.0%Probability of exploitation in the next 30 days