Description
Gotenberg is an API for converting document formats. In 8.29.1 and earlier, Gotenberg uses dlclark/regexp2 to compile user-supplied scope patterns without setting a proper timeout. Users with access to features using this logic can hang workers indefinitely.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-fmwg-qcqh-m992 | Gotenberg Vulnerable to ReDoS via extraHttpHeaders scope feature |
References
History
Tue, 07 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Gotenberg is an API for converting document formats. In 8.29.1 and earlier, Gotenberg uses dlclark/regexp2 to compile user-supplied scope patterns without setting a proper timeout. Users with access to features using this logic can hang workers indefinitely. | |
| Title | Gotenberg has a ReDoS via extraHttpHeaders scope feature | |
| Weaknesses | CWE-1333 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-07T14:24:21.651Z
Reserved: 2026-04-02T19:25:52.193Z
Link: CVE-2026-35458
No data.
Status : Received
Published: 2026-04-07T15:17:43.733
Modified: 2026-04-07T15:17:43.733
Link: CVE-2026-35458
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA