PatchDay Alert

CVE

CVE-2026-42596

0field notes · 1digest CVSS 9.4


Daily digests

Gotenberg's downloadFrom and webhook features have a server-side request forgery (SSRF) bug that bypasses the default deny-list. An unauthenticated attacker can make your Gotenberg instance fetch internal URLs, potentially reaching cloud metadata endpoints, internal APIs, or other services behind your firewall. CVSS 9.4, so treat this seriously.

Get the digest

Free. Weekday mornings. Plain English CVE triage.

Check your inbox to confirm.