CVE-2026-42589Disclosure(thecodingmachine / gotenberg)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch thecodingmachine gotenberg systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg's /forms/pdfengines/metadata/write HTTP endpoint accepts a JSON metadata object and passes its keys directly to ExifTool via the go-exiftool library. No validation is performed on key characters. A \n embedded in a JSON key splits the ExifTool stdin stream into a new argument line, allowing an attacker to inject arbitrary ExifTool flags — including -if, which evaluates Perl expressions. This achieves unauthenticated OS command execution in a single HTTP request. The response is HTTP 200 with a valid PDF, making the attack transparent to basic monitoring. This vulnerability is fixed in 8.31.0.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gotenberg

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 20 mentions across 10 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 5d ago at 4 mentions (2026-10-03); latest day: 1
  • 20 total mentions across 10 days

Affected systems

Products
gotenberg

Deep dive

Activity timeline20 mentions / 10d
01234Mentions · 2026-05-07: 1Mentions · 2026-05-14: 1Mentions · 2026-07-02: 1Mentions · 2026-09-22: 1Mentions · 2026-10-03: 4Mentions · 2026-10-04: 2Mentions · 2026-10-05: 4Mentions · 2026-10-06: 4Mentions · 2026-10-07: 1Mentions · 2026-10-10: 1Active Exploitation · 2026-07-02: 1Active Exploitation · 2026-09-22: 1Patch / Workaround · 2026-07-02: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-14: 1Technical Details · 2026-07-02: 1Technical Details · 2026-09-22: 105-0705-1407-0209-2210-0310-0410-0510-0610-0710-10
Signal classification2 categories
Disclosure
250.0%
Active Exploitation
250.0%
Referenced assets15 URLs
Classification over time
DateTotalLabels
2026-05-071
Disclosure1
2026-05-141
Disclosure1
2026-07-021
Active Exploitation1
2026-09-221
Active Exploitation1
Full discourse20 posts
  • Dark Web Informer@DarkWebInformer

    🚨 PoC released for an unauthenticated Gotenberg RCE chain PoC: https://github.com/HackfutSecRoot/-GOTENBERG-RCE-CHAIN CVE chain: CVE-2026-42589 + CVE-2026-40281 The exploit targets the /forms/pdfengines/metadata/write endpoint and chains metadata injection flaws to achieve remote command execution. Affected: Gotenberg ≤ 8.30.1 Patched: Gotenberg ≥ 8.31.0 The PoC includes vulnerability detection, interactive command execution, reverse shell support, and multi-target scanning.

    2210823010.0K
    242.7K followersView on X
  • !Manan@0xManan

    Your PDF microservice runs ExifTool. ExifTool runs Perl. Guess who controls the Perl now. CVE-2026-40281 (CVSS 10.0) + CVE-2026-42589 : Gotenberg ≤ 8.30.1, the Docker PDF-conversion API half the stack quietly depends on. Chain: unauth `POST /forms/pdfengines/metadata/write` → a `\n` inside a JSON metadata key splits ExifTool's stdin into a new argument → smuggle `-if system('…')||1` → Perl eval → your command runs as the container user. One request. It answers HTTP 200 with a valid PDF, so your monitoring sees a successful conversion and nothing else. The 8.30.1 "fix" only sanitized keys - 40281 is the same trick through metadata values. Patch 8.31.0. PoC + nuclei template: https://github.com/fineman999/POC_CVE-2026-42589 Still exposing a PDF renderer with no auth in front of it? Bold. #infosec #RCE #CVE

    26041222.3K
    2.2K followersView on X
  • ThreatWire@ThreatWire_

    🚨 PoC RELEASED: A public exploit has been published for CVE-2026-42589, a critical unauthenticated RCE in Gotenberg. The vulnerability affects Gotenberg versions before 8.31.0 and stems from unsafe handling of metadata keys passed to ExifTool. An attacker with network access can potentially achieve arbitrary code execution without authentication. 🔴 CVSS: 9.8 CRITICAL ⚠️ No authentication required ⚠️ Network exploitable ✅ Fixed in Gotenberg 8.31.0 A public PoC is now available, increasing the risk for exposed Gotenberg deployments. 🔴 Upgrade to Gotenberg 8.31.0 or later. PoC: https://github.com/hackfutsecroot/-gotenberg-rce-chain Source: https://github.com/gotenberg/gotenberg/security/advisories/GHSA-rqgh-gxv4-6657 #CVE #CyberSecurity #InfoSec #Gotenberg #RCE #DevSecOps

    1812031.4K
    1.8K followersView on X
  • ExploitGrid@exploitgrid

    ExploitGrid Daily Digest 🚨 Top Exploits: CVE-2024-51482 (CVSS: 10) zoneminder CVE-2025-55182 (CVSS: 10) Meta CVE-2026-103956 (CVSS: 10) AWS CVE-2026-40281, CVE-2026-42589 (CVSS: 9.9) gotenberg CVE-2018-7600 (CVSS: 9.8) n/a ..🧵👇

    110120453
    377 followersView on X
  • ExploitGrid@exploitgrid

    CVE-2026-42589 is a CVSS 9.8 unauthenticated RCE in Gotenberg <8.31.0. An attacker can inject ExifTool flags through the metadata endpoint and execute OS commands with a single HTTP request. Public exploits are available. #CyberSecurity #CVE #RCE https://exploitgrid.net/vulnerabilities/CVE-2026-42589

    12083351
    378 followersView on X
  • FOFA@fofabot

    ⚠️⚠️ CVE-2026-42589 (CVSS 9.8) + CVE-2026-40281 (CVSS 10.0): unauthenticated argument injection in Gotenberg PDF engine metadata-write endpoint → RCE 🔗FOFA Link: https://en.fofa.info/result?qbase64=Ym9keV9oYXNoPSItMTM3MzU2NzI2MCI= 🎯6.6K+ Results are found on http://en.fofa.info in the past year. FOFA Query: body_hash="-1373567260" PoC: https://threatcluster.io/article/cve-2026-40281-exploit-83d22498 🔖Refer: https://dbu.gs/vulnerability/PT-2026-36917 #OSINT #FOFA #CyberSecurity #Vulnerability

    120631.2K
    14.8K followersView on X
  • Upwind Security MDR@UpwindMDR
    Active Exploitation

    🚨 We're observing active exploitation attempts targeting CVE-2026-42589. This critical vulnerability affects Gotenberg (<8.31.0) and allows unauthenticated remote code execution (RCE) via the /forms/pdfengines/metadata/write endpoint by abusing ExifTool metadata processing. Organizations running exposed instances should patch immediately.

    Post summary

    Active exploitation of CVE-2026-42589 is occurring in Gotenberg, enabling unauthenticated RCE via the metadata write endpoint; urgent patching is required.

    01090176
    296 followersView on X
  • dbugs@ptdbugs

    A PoC/exploit has been discovered for vulnerability CVE-2026-42589 PT ID: PT-2026-38380 Read on dbugs: https://dbu.gs/vulnerability/PT-2026-38380 Vendor: Gotenberg Product: Gotenberg Description: Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg's /forms/pdfengines/metadata/write HTTP endpoint accepts a JSON metadata object and passes its keys directly to ExifTool via the go-exiftool library. No validation is performed on key characters. A \n embedded in a JSON key splits the ExifTool stdin stream into a new argument line, allowing an attacker to inject arbitrary ExifTool flags — including -if, which evaluates Perl expressions. This achieves unauthenticated OS command execution in a single HTTP request. The response is HTTP 200 with a valid PDF, making the attack transparent to basic monitoring. This vulnerability is fixed in 8.31.0. Link: https://github.com/hackfutsecroot/-gotenberg-rce-chain

    00052678
    3.7K followersView on X
  • ExploitGrid@exploitgrid

    Public PoC released for CVE-2026-42589. Gotenberg &lt;8.31.0 allows unauthenticated RCE through ExifTool metadata key injection. CVSS 9.8 | 3 exploits tracked Fixed in 8.31.0 Full intelligence: https://exploitgrid.net/vulnerabilities/CVE-2026-42589 #CyberSecurity #Gotenberg

    10041225
    378 followersView on X
  • ExploitGrid@exploitgrid

    #ExploitGrid Daily Digest 🚨 Top Exploits: CVE-2026-40281 (CVSS: 10) gotenberg CVE-2026-40281 (CVSS: 10) gotenberg CVE-2026-40281, CVE-2026-42589 (CVSS: 9.9) gotenberg CVE-2017-7921 (CVSS: 9.8) n/a CVE-2026-103752 (CVSS: 9.8) ..🧵👇

    11030180
    378 followersView on X
  • ExploitGrid@exploitgrid

    #ExploitGrid Daily Digest 🚨 Top Exploits: CVE-2026-40281 (CVSS: 10) gotenberg CVE-2026-40281 (CVSS: 10) gotenberg CVE-2026-40281, CVE-2026-42589 (CVSS: 9.9) gotenberg CVE-2017-7921 (CVSS: 9.8) n/a CVE-2026-103752 (CVSS: 9.8) ..🧵👇

    10020204
    378 followersView on X
  • ExploitGrid@exploitgrid

    ├ CVE-2026-40281 + CVE-2026-42589 (Gotenberg) · Full RCE chain PoC, still unpatched └ CVE-2018-7600 — Drupalgeddon2 · PoC live, 8 years old and still working

    1000040
    377 followersView on X
  • ExploitGrid@exploitgrid

    💀 CRITICAL Exploits Trending ├ CVE-2024-51482 — ZoneMinder · PoC live ├ CVE-2025-55182 — Meta/React "React2Shell" · PoC live ├ CVE-2026-103956 — AWS Loom · Unauth bypass PoC live ├ CVE-2026-40281 + CVE-2026-42589 (Gotenberg) · Full RCE chain PoC, still unpatched

    1000071
    377 followersView on X
  • ExploitGrid@exploitgrid

    [EXPLOIT] CVE-2026-40281, CVE-2026-42589 [CRITICAL/PoC] CVSS: 9.9 | Vendor: #gotenberg -GOTENBERG-RCE-CHAIN 🔗 https://exploitgrid.net/exploits/fd19e172-0683-412e-bb16-fb316739db3c

    1000085
    377 followersView on X
  • ExploitGrid@exploitgrid

    [EXPLOIT] CVE-2026-40281, CVE-2026-42589 [CRITICAL/PoC] CVSS: 9.9 | Vendor: #gotenberg CVE-2026-42589xCVE-2026-40281-PoC 🔗 https://exploitgrid.net/exploits/93ceab76-8980-4632-9934-400a7a5706fb

    1000070
    378 followersView on X
  • ExploitGrid@exploitgrid

    💀 CRITICAL Exploits Trending ├ CVE-2026-40281 (Gotenberg) · 2 separate PoCs live ├ CVE-2026-40281 + CVE-2026-42589 (Gotenberg) · chained PoC (9.9) ├ CVE-2017-7921 · PoC live (9.8) └ CVE-2026-103752 — WP Authorizer · Privilege escalation PoC live

    1000071
    378 followersView on X
  • ExploitGrid@exploitgrid

    [EXPLOIT] CVE-2026-40281, CVE-2026-42589 [CRITICAL/PoC] CVSS: 9.9 | Vendor: #gotenberg CVE-2026-42589xCVE-2026-40281-PoC 🔗 https://exploitgrid.net/exploits/93ceab76-8980-4632-9934-400a7a5706fb

    1000067
    378 followersView on X
  • The Hunters Ledger@Hunters_Ledger
    Active Exploitation

    One operator hit 198 Gotenberg endpoints with CVE-2026-42589 in 54 minutes, from 107[.]175[.]69[.]137. The rule you'd write from the exploit source never fires: the newline hits the wire JSON-escaped, decoded only after a sensor passed it. https://the-hunters-ledger.com/reports/gotenberg-rce-cryptomining-107-175-69-137/ #ThreatIntel

    Post summary

    The tweet reports in-the-wild exploitation of CVE-2026-42589 targeting Gotenberg for cryptomining, highlighting detection evasion via JSON-escaped newlines.

    0000048
    43 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🚨 CRITICAL — CVE-2026-42589 Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg's /forms/pdfengines/metadata/writ… CVSS 9.8 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-42589 #Docker #CyberSecurity #InfoSec

    Post summary

    A new critical vulnerability (CVE-2026-42589) in Gotenberg, a Docker-based PDF processing API, has been disclosed with a CVSS score of 9.8 and currently no patch available. Further details and analysis are available at the provided link.

    0000044
    90 followersView on X
  • Technology Interpreters, Inc.@TechTranslators
    Disclosure

    Today (Thu, May 7): 1 KEV add, 12 critical CVEs. Ivanti EPMM admin RCE went out earlier. Long tail: - Gotenberg unauth RCE (CVE-2026-42589, 9.8) - intercom-client/intercom-php — compromised npm + Composer packages - Rancher Fleet Helm bypass (CVE-2026-41050, 9.9)

    Post summary

    The tweet announces the addition of 12 critical CVEs—including an unauthenticated RCE in Gotenberg and a Helm bypass in Rancher Fleet—without evidence of exploitation or remediation.

    0000059
    34 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appthecodingmachinegotenberg---

Explore more