CVE-2026-35458: Thecodingmachine Gotenberg

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Gotenberg is an API for converting document formats. In 8.29.1 and earlier, Gotenberg uses dlclark/regexp2 to compile user-supplied scope patterns without setting a proper timeout. Users with access to features using this logic can hang workers indefinitely.

Affected products

Published 2026-04-07. Last modified 2026-06-17.