CVE Database
/

CVE-2026-35458

Back to search

CVE-2026-35458

Published: Apr 7, 2026

Modified: Apr 9, 2026

PUBLISHED

Description

Gotenberg is an API for converting document formats. In 8.29.1 and earlier, Gotenberg uses dlclark/regexp2 to compile user-supplied scope patterns without setting a proper timeout. Users with access to features using this logic can hang workers indefinitely.

VendorProductVersions

gotenberg

gotenberg

affected
<= 8.29.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now