CVE-2026-55229 Details
Description
Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.34.0, Gotenberg's /forms/libreoffice/convert endpoint allows a specially crafted document to cause LibreOffice to automatically retrieve external HTTP(S) resources and local file resources during document conversion, enabling blind SSRF and limited local file disclosure via linked image resource loading. This issue is fixed in version 8.34.0.
A vulnerability in Gotenberg prior to version 8.34.0 allows for blind server-side request forgery (SSRF) and limited local file disclosure through the LibreOffice conversion endpoint. This issue arises because LibreOffice can be manipulated to fetch external resources or local files linked in the document, during the conversion process. The vulnerability is present in Gotenberg versions prior to 8.34.0.
Users can update to Gotenberg version 8.34.0 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 10, 2026CISA-ADP
Assessed Jul 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/gotenberg/gotenberg/security/advisories/GHSA-2mrg-35hw-x3x9 | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/gotenberg/gotenberg/commit/98fc40347885ad510a311b990a73397c6d4143db | [email protected] | Source CodeVendor |
| https://github.com/gotenberg/gotenberg/releases/tag/v8.34.0 | [email protected] | Release NotesVendor |
| https://github.com/gotenberg/gotenberg/security/advisories/GHSA-2mrg-35hw-x3x9 | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Gotenberg | 8.33.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 13, 2026 | CVE Modified | CISA-ADP |
| Jul 10, 2026 | New CVE Received | [email protected] |
Volerion