CVE-2026-39383Disclosure(thecodingmachine / gotenberg)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Gotenberg is an API-based document conversion tool. In version 8.29.1, an unauthenticated attacker with network access can force the server to make outbound HTTP POST requests to arbitrary internal or external destinations by supplying a crafted URL in the Gotenberg-Webhook-Url request header. The FilterDeadline function in filter.go is intended to gate outbound URLs, but when both the allow-list and deny-list are empty (the default configuration), it returns nil unconditionally and permits any URL. This is a blind SSRF: Gotenberg POSTs the converted document to the webhook URL and only checks whether the response status code is an error, but never returns the target's response body to the attacker. An attacker can use this to probe internal network infrastructure by observing whether the error callback is invoked, force POST requests against internal services that perform side effects, and confirm reachability of cloud metadata endpoints. The retryable HTTP client issues up to 4 automatic retries per request, amplifying each probe. This issue has been fixed in version 8.31.0. As a workaround, configure the GOTENBERG_API_WEBHOOK_ALLOW_LIST environment variable to restrict webhook URLs to known receivers, or set GOTENBERG_API_WEBHOOK_DENY_LIST to block RFC-1918 and link-local address ranges.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gotenberg

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-05); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
gotenberg

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-05: 2Mentions · 2026-05-06: 1Technical Details · 2026-05-05: 2Technical Details · 2026-05-06: 105-0505-06
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-052
Disclosure2
2026-05-061
Disclosure1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-39383 Unauthenticated Server-Side Request Forgery in Gotenberg 8.29.1 via Webhook URL https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-39383

    Post summary

    This alert announces CVE-2026-39383, an unauthenticated SSRF vulnerability in Gotenberg 8.29.1 triggered via webhook URLs, with no PoC, exploit code, patch, or active exploitation noted.

    0000040
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-39383 Gotenberg is an API-based document conversion tool. In version 8.29.1, an unauthenticated attacker with network access can force the server to make outbound HTTP POST… https://www.cve.org/CVERecord?id=CVE-2026-39383 ----- Traducción: CVE-2026-39383 Got… http://infoflow.cloud`

    Post summary

    CVE-2026-39383 is a disclosure of a vulnerability in Gotenberg where unauthenticated attackers can force outbound POST requests. No specific exploit, patch, or active exploitation details are provided.

    0000039
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-39383 Gotenberg is an API-based document conversion tool. In version 8.29.1, an unauthenticated attacker with network access can force the server to make outbound HTTP POST… https://www.cve.org/CVERecord?id=CVE-2026-39383

    Post summary

    The text announces CVE-2026-39383, describing how an unauthenticated attacker can force Gotenberg to make outbound HTTP POST requests, but it does not provide a PoC, exploit code, patch, or evidence of active exploitation.

    00000204
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appthecodingmachinegotenberg---

Explore more