Junglewise Threat Intelligence

CVE-2026-42594: Gotenberg race condition and process crash in webhook middleware

CVE-2026-42594 · Severity: high · CVSS 7.5 · Published 2026-05-14

Technologies: Gotenberg, github.com/gotenberg/gotenberg/v8 (Go), github.com/gotenberg/gotenberg/v7 (Go). Vendors: Gotenberg, Go.

Executive brief

Gotenberg is a specialized tool used to convert various file formats into PDFs via a web interface. A flaw in how the system handles background tasks (webhooks) allows an unauthenticated attacker to crash the entire service by sending a specific sequence of requests. This results in a denial-of-service, causing all active file conversions to fail and disrupting document processing workflows until the service is manually or automatically restarted.

Technical details

A race condition exists in the webhook middleware due to improper management of the Echo framework's context pool. When a webhook request is processed asynchronously, the middleware spawns a goroutine that retains a reference to the 'echo.Context' after the synchronous handler has already returned and recycled the context back into the 'sync.Pool'. If a concurrent request reclaims that context and resets it, the background goroutine may attempt an unchecked type assertion on a nil 'logger' entry within the 'hardTimeoutMiddleware'. Because this occurs outside of a recovery scope, it triggers a process-wide panic and crash. Attackers can reliably trigger this with a relatively low volume of concurrent webhook and status requests. The issue is resolved in version 8.32.0 by implementing guarded type assertions and better goroutine recovery.

Affected products

  • Gotenberg Gotenberg < 8.32.0

Timeline

  • 2026-04-30: advisory: GitHub Security Advisory published
  • 2026-05-14: disclosed: NVD publication date

References

Related threats