logo

Maximum Severity Flaw: How a Newline Character Shattered Gotenberg’s PDF Security

ID: 905ebe10-4c9b-50b6-8c26-67550c975126

STIX ID: report--905ebe10-4c9b-50b6-8c26-67550c975126

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-05-05

Date Updated: 2026-05-05

Author: Ddos

...
...

A security disclosure details four critical vulnerabilities in Gotenberg (Docker-based document-to-PDF API), including CVE-2026-40281 (CVSS 10) that enables unauthenticated remote code execution via newline injection into ExifTool metadata, additional high-severity RCE and SSRF bypasses (CVE-2026-42589, CVE-2026-40280, CVE-2026-42596), and demonstrates how attackers can rename/overwrite files, reach internal services/cloud metadata, and establish persistence; all issues are fixed in Gotenberg 8.32.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.