Gotenberg是Gotenberg团队开源的一个开发人员友好的 API。用于将多种文档格式转换为 PDF 文件。 Gotenberg 8.34.0之前版本存在服务端请求伪造漏洞,该漏洞源于/forms/libreoffice/convert端点允许特制文档在转换过程中自动检索外部HTTP(S)资源和本地文件资源,可能导致盲目服务端请求伪造和有限本地文件泄露。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Gotenberg before 8.34.0 allows SSRF and limited local file disclosure via its /forms/libreoffice/convert endpoint. When LibreOffice is used to convert user-uploaded DOCX files, external relationships within the document (such as a:blip r:link TargetMode="External") can instruct LibreOffice to fetch local resources (file://) or remote resources (http/https), which are then included as images in the generated PDF. This can disclose the contents of local files LibreOffice can open as images, or allow outbound requests to attacker-controlled endpoints. Version 8.34.0 disables resolution of external resources during document conversion to mitigate the vulnerability. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-55229.yaml | POC Details |
No comments yet