Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-fmwg-qcqh-m992 | Gotenberg Vulnerable to ReDoS via extraHttpHeaders scope feature |
Tue, 14 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Thecodingmachine
Thecodingmachine gotenberg |
|
| CPEs | cpe:2.3:a:thecodingmachine:gotenberg:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Thecodingmachine
Thecodingmachine gotenberg |
Thu, 09 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 08 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gotenberg
Gotenberg gotenberg |
|
| Vendors & Products |
Gotenberg
Gotenberg gotenberg |
Tue, 07 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Gotenberg is an API for converting document formats. In 8.29.1 and earlier, Gotenberg uses dlclark/regexp2 to compile user-supplied scope patterns without setting a proper timeout. Users with access to features using this logic can hang workers indefinitely. | |
| Title | Gotenberg has a ReDoS via extraHttpHeaders scope feature | |
| Weaknesses | CWE-1333 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-09T14:20:52.933Z
Reserved: 2026-04-02T19:25:52.193Z
Link: CVE-2026-35458
Updated: 2026-04-09T14:20:43.107Z
Status : Analyzed
Published: 2026-04-07T15:17:43.733
Modified: 2026-04-14T20:27:23.103
Link: CVE-2026-35458
No data.
OpenCVE Enrichment
Updated: 2026-04-15T16:30:09Z
Github GHSA