CVE-2026-42589·Docker vulnerability
Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg's /forms/pdfengines/metadata/write HTTP endpoint accepts a JSON metadata object and passes its keys directly to ExifTool via the go-exiftool library. No validation is performed on key characters. A \n embedded in a JSON key splits the ExifTool stdin stream into a new argument line, allowing an attacker to inject arbitrary ExifTool flags — including -if, which evaluates Perl expressions. This achieves unauthenticated OS command execution in a single HTTP request. The response is HTTP 200 with a valid PDF, making the attack transparent to basic monitoring. This vulnerability is fixed in 8.31.0.
- Severity
- critical
- Software
- Docker
- Fixed in
- 8.31.0
- Published
- 2026-05-14
Affected versions
Until: 8.31.0
Fixed in: 8.31.0
How to fix this CVE
Upgrade Docker to version 8.31.0 or later to patch the metadata endpoint input validation flaw that allows command injection through ExifTool. If you are running Gotenberg within Docker, ensure the container image is rebuilt with the patched version. Immediate patching is critical as this vulnerability permits unauthenticated remote code execution with minimal detection.
sudo dnf update docker-ceDefensia detects this vulnerability
What an exploitation attempt looks like
Sample log line indicative of exploitation attempts:
POST /forms/pdfengines/metadata/write.*\n.*-if|POST /forms/pdfengines/metadata/write.*Content-Type: application/json.*\\n.*(?:perl|system|exec)WAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Block POST requests to /forms/pdfengines/metadata/write with JSON payloads containing literal newline characters (\n) or URL-encoded newlines (%0A, %0D%0A) in JSON keys. Implement strict JSON schema validation to reject keys with control characters.How to check if you are affected
- Check installed Docker version: docker --version or docker version | grep -i version
- Identify Gotenberg containers: docker ps --filter 'ancestor=gotenberg*' --format '{{.Image}} {{.ID}}'
- Inspect Gotenberg image tag: docker inspect <container_id> | grep -i 'Image.*gotenberg'
- Verify patch installation: docker exec <container_id> /gotenberg --version and confirm version >= 8.31.0
FAQ
What is CVE-2026-42589?
CVE-2026-42589 is a critical unauthenticated remote code execution vulnerability in Gotenberg's PDF metadata endpoint that fails to sanitize JSON keys, allowing newline injection to bypass ExifTool argument parsing and execute arbitrary Perl expressions.
Is CVE-2026-42589 being actively exploited?
No, this vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities catalog and no public exploit code is available, but the low complexity of the attack makes it a high-priority remediation target.
What versions of Docker are affected by CVE-2026-42589?
All versions of Gotenberg prior to 8.31.0 are affected; the vulnerability exists in the /forms/pdfengines/metadata/write endpoint regardless of Docker version, but depends on Gotenberg being deployed as a container.
How do I check if my server is vulnerable to CVE-2026-42589?
Run `docker images | grep gotenberg` and check the tag version; if it is below 8.31.0, pull the latest image with `docker pull gotenberg:latest` and redeploy the container.
Does Defensia detect CVE-2026-42589?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Docker or Gotenberg is installed on a monitored server, CVE-2026-42589 will appear in your dashboard with remediation steps.
Related Docker CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-42589. Free for 1 server.
Get started free