CVE Explorer
CVE-2026-39383
Gotenberg is an API-based document conversion tool. In version 8.29.1, an unauthenticated attacker with network access can force the server to make outbound HTTP POST requests to arbitrary internal or external destinations by supplying a crafted URL in the Gotenberg-Webhook-Url request header. The FilterDeadline function in filter.go is intended to gate outbound URLs, but when both the allow-list and deny-list are empty (the default configuration), it returns nil unconditionally and permits any
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"gotenberg","vendor":"gotenberg","versions":[{"status":"affected","version":"< 8.31.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:be8267a548ea62534dafc782dd93cc3b16711f7bf451306a62ff00fb403751c3 · sha256:2f514e7e11f42022… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":6.9,"baseSeverity":"MEDIUM","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:be8267a548ea62534dafc782dd93cc3b16711f7bf451306a62ff00fb403751c3 · sha256:2f514e7e11f42022… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-918","description":"CWE-918: Server-Side Request Forgery (SSRF)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:be8267a548ea62534dafc782dd93cc3b16711f7bf451306a62ff00fb403751c3 · sha256:2f514e7e11f42022… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/gotenberg/gotenberg/security/advisories/GHSA-5vh4-rgv7-p9g4","tags":["x_refsource_CONFIRM"],"url":"https://github.com/gotenberg/gotenberg/security/advisories/GHSA-5vh4-rgv7-p9g4"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:be8267a548ea62534dafc782dd93cc3b16711f7bf451306a62ff00fb403751c3 · sha256:2f514e7e11f42022… · /containers/cna/references/0
{"tags":["exploit"],"url":"https://github.com/gotenberg/gotenberg/security/advisories/GHSA-5vh4-rgv7-p9g4"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:be8267a548ea62534dafc782dd93cc3b16711f7bf451306a62ff00fb403751c3 · sha256:2f514e7e11f42022… · /containers/adp/0/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.