Junglewise Threat Intelligence

CVE-2026-42592: Gotenberg DNS rebinding SSRF in Chromium URL conversion

CVE-2026-42592 · Severity: medium · CVSS 5.3 · Published 2026-05-14

Technologies: Gotenberg, github.com/gotenberg/gotenberg/v8 (Go), github.com/gotenberg/gotenberg/v7 (Go). Vendors: Gotenberg, Go.

Executive brief

Gotenberg is a tool used to convert web pages and documents into PDF files. A security flaw allows attackers to bypass safety filters and force the system to access internal company servers or private cloud data that should be off-limits. By tricking the system into connecting to these private addresses, an attacker can capture sensitive internal information and receive it back in the form of a generated PDF.

Technical details

A Time-of-Check Time-of-Use (TOCTOU) vulnerability exists in Gotenberg's Chromium-based URL conversion. The 'FilterOutboundURL' function validates a hostname against a private-address deny-list but discards the resolved IP address. Chromium then performs its own independent DNS resolution when navigating. An attacker controlling a DNS server with a short TTL can provide a public IP during the initial validation and a private/internal IP (such as 127.0.0.1 or 169.254.169.254) during Chromium's actual connection phase. This DNS rebinding attack allows unauthenticated remote attackers to perform Server-Side Request Forgery (SSRF) and exfiltrate internal service responses via the rendered PDF output. The issue is fixed in version 8.32.0 by ensuring resolved IPs are pinned.

Affected products

  • Gotenberg Gotenberg < 8.32.0

Timeline

  • 2026-04-30: advisory: GitHub security advisory published by maintainers
  • 2026-05-14: disclosed: CVE published to NVD
  • 2026-05-14: patched: Fix released in version 8.32.0

References

Related threats