Maximum Severity Flaw: How a Newline Character Shattered Gotenberg’s PDF Security
ID: 905ebe10-4c9b-50b6-8c26-67550c975126
STIX ID: report--905ebe10-4c9b-50b6-8c26-67550c975126
Feed Name: securityonline.info
A security disclosure details four critical vulnerabilities in Gotenberg (Docker-based document-to-PDF API), including CVE-2026-40281 (CVSS 10) that enables unauthenticated remote code execution via newline injection into ExifTool metadata, additional high-severity RCE and SSRF bypasses (CVE-2026-42589, CVE-2026-40280, CVE-2026-42596), and demonstrates how attackers can rename/overwrite files, reach internal services/cloud metadata, and establish persistence; all issues are fixed in Gotenberg 8.32.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
