Executive brief
Gotenberg is a tool used to convert various file formats into PDFs via an API. A security flaw allows unauthorized users to force the Gotenberg server to send data to unintended internal or external web addresses. This could be used by attackers to map out a company's private internal network or interact with internal services that are not supposed to be accessible from the internet.
Technical details
A blind Server-Side Request Forgery (SSRF) exists in Gotenberg version 8.29.1 due to an insecure default configuration in the FilterDeadline function within filter.go. When both the allow-list and deny-list are empty, the function fails open and permits any URL provided in the 'Gotenberg-Webhook-Url' header. An unauthenticated remote attacker can exploit this to send POST requests containing converted documents to arbitrary destinations. While the attacker cannot see the response body, they can perform internal network reconnaissance by monitoring error callbacks and trigger side effects on internal services. The vulnerability is amplified by a retryable HTTP client that issues up to four automatic retries. This issue is fixed in version 8.31.0.
Affected products
- Gotenberg Gotenberg 8.29.1
Timeline
- 2026-04-04: other: Vulnerability discovered
- 2026-04-30: advisory: GitHub Security Advisory published
- 2026-05-05: disclosed: CVE published to NVD
- 2026-08-31: patched: Fixed in version 8.31.0