CVE-2026-35458: Thecodingmachine Gotenberg
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Gotenberg is an API for converting document formats. In 8.29.1 and earlier, Gotenberg uses dlclark/regexp2 to compile user-supplied scope patterns without setting a proper timeout. Users with access to features using this logic can hang workers indefinitely.
Affected products
- Thecodingmachine Gotenberg: before 8.29.1 (fixed in 8.29.1)
Published 2026-04-07. Last modified 2026-06-17.