<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T17:17:37.249766+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-308768</id>
    <title>EUVD-2026-308768</title>
    <updated>2026-10-07T17:17:37.296909+00:00</updated>
    <content>EUVD-2026-308768</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-308768"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-39383</id>
    <title>fkie_cve-2026-39383</title>
    <updated>2026-10-07T17:17:37.296950+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Gotenberg is an API-based document conversion tool. In version 8.29.1, an unauthenticated attacker with network access can force the server to make outbound HTTP POST requests to arbitrary internal or external destinations by supplying a crafted URL in the Gotenberg-Webhook-Url request header. The FilterDeadline function in filter.go is intended to gate outbound URLs, but when both the allow-list and deny-list are empty (the default configuration), it returns nil unconditionally and permits any URL.</p>
<p>This is a blind SSRF: Gotenberg POSTs the converted document to the webhook URL and only checks whether the response status code is an error, but never returns the target's response body to the attacker. An attacker can use this to probe internal network infrastructure by observing whether the error callback is invoked, force POST requests against internal services that perform side effects, and confirm reachability of cloud metadata endpoints. The retryable HTTP client issues up to 4 automatic retries per request, amplifying each probe.</p>
<p>This issue has been fixed in version 8.31.0. As a workaround, configure the GOTENBERG_API_WEBHOOK_ALLOW_LIST environment variable to restrict webhook URLs to known receivers, or set GOTENBERG_API_WEBHOOK_DENY_LIST to block RFC-1918 and link-local address ranges.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-39383"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5vh4-rgv7-p9g4</id>
    <title>GHSA-5vh4-rgv7-p9g4 — Gotenberg Vulnerable to Unauthenticated SSRF via Unfiltered Webhook URL</title>
    <updated>2026-10-07T17:17:37.296996+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/gotenberg/gotenberg/v8</p>
<p># CVE Report — Unauthenticated SSRF via Unfiltered Webhook URL in Gotenberg</p>
<p>## Severity</p>
<p>| Field     | Value                                  |
|-----------|----------------------------------------|
| CVSS v3.1 | **8.6 High**                           |
| Vector    | `AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N` |
| CWE       | CWE-918 — Server-Side Request Forgery  |
| Auth      | None                                   |</p>
<p>**Affected:** Gotenberg 8.29.1 — default `gotenberg/gotenberg:8` Docker image.</p>
<p>---</p>
<p>## Impact</p>
<p>An unauthenticated attacker with network access to Gotenberg can force it to make outbound HTTP POST requests to any internal or external destination by supplying an arbitrary URL in the `Gotenberg-Webhook-Url` request header.</p>
<p>**This is a blind SSRF.** Gotenberg POSTs the converted document to the webhook URL and checks only whether the response status code is an error (&gt;= 400). The response body from the SSRF target is never forwarded to the attacker. The `Gotenberg-Webhook-Error-Url` header — if supplied — receives the original converted PDF when the webhook POST fails, not the target's response body.</p>
<p>The practical impact is therefore:</p>
<p>- **Internal network probing:** if the error URL is NOT called, the target returned 2xx → host and port are open and accepting POST requests. If the error URL IS called, the target returned 4xx/5xx or timed out → port closed or service rejected the request. This allows mapping internal infrastructure one request at a time. 
- **Forc…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5vh4-rgv7-p9g4"/>
  </entry>
</feed>
