Executive brief
Gotenberg is a tool used to convert web pages and documents into PDF files. A security flaw allows attackers to bypass safety filters and force the system to access internal company servers or private cloud data that should be off-limits. By tricking the system into connecting to these private addresses, an attacker can capture sensitive internal information and receive it back in the form of a generated PDF.
Technical details
A Time-of-Check Time-of-Use (TOCTOU) vulnerability exists in Gotenberg's Chromium-based URL conversion. The 'FilterOutboundURL' function validates a hostname against a private-address deny-list but discards the resolved IP address. Chromium then performs its own independent DNS resolution when navigating. An attacker controlling a DNS server with a short TTL can provide a public IP during the initial validation and a private/internal IP (such as 127.0.0.1 or 169.254.169.254) during Chromium's actual connection phase. This DNS rebinding attack allows unauthenticated remote attackers to perform Server-Side Request Forgery (SSRF) and exfiltrate internal service responses via the rendered PDF output. The issue is fixed in version 8.32.0 by ensuring resolved IPs are pinned.
Affected products
- Gotenberg Gotenberg < 8.32.0
Timeline
- 2026-04-30: advisory: GitHub security advisory published by maintainers
- 2026-05-14: disclosed: CVE published to NVD
- 2026-05-14: patched: Fix released in version 8.32.0