CVE-2026-42596·Docker vulnerability
Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, the default deny-lists used by Gotenberg's downloadFrom feature and webhook feature are bypassable. Because the filter is regex-based and case-sensitive, an unauthenticated attacker can supply URLs such as http://[::ffff:127.0.0.1]:... and reach loopback or private HTTP services that the default deny-list is intended to block. This crosses a real security boundary because an external caller can force the server to make outbound requests to internal-only targets. This vulnerability is fixed in 8.31.0.
- Severity
- critical
- Software
- Docker
- Fixed in
- 8.31.0
- Published
- 2026-05-14
Affected versions
Until: 8.31.0
Fixed in: 8.31.0
How to fix this CVE
Update Docker to version 8.31.0 or later to patch the Gotenberg URL filter bypass vulnerability in the downloadFrom and webhook features. The vulnerability allows attackers to bypass the regex-based deny-list by using alternative IPv6 loopback notation (e.g., [::ffff:127.0.0.1]) to reach internal services. Apply this update immediately to prevent unauthorized outbound requests to private HTTP services.
sudo dnf update docker-ce docker-ce-cli docker-buildx-plugin docker-compose-pluginDefensia detects this vulnerability
What an exploitation attempt looks like
Sample log line indicative of exploitation attempts:
POST|GET.*/(downloadFrom|webhook).*HTTP.*(?:::ffff:|::1|localhost|127\.0\.0\.|169\.254\.|10\.0\.0\.|172\.(1[6-9]|2[0-9]|3[01])\.|192\.168\.)WAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Implement strict URL validation on all incoming requests to Gotenberg endpoints (downloadFrom, webhook). Enforce a whitelist of allowed destination domains and block requests containing IPv6 loopback notation ([::ffff:127.0.0.1], [::1]), private IP ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16), and link-local addresses (169.254.0.0/16). Apply case-sensitive matching to ensure bypass attempts with mixed-case schemes are rejected.How to check if you are affected
- Check installed Docker version: docker --version
- Verify Gotenberg component version: docker inspect $(docker ps -q --filter 'ancestor=gotenberg') 2>/dev/null | grep -i version || echo 'Gotenberg container not running'
- Search Docker daemon logs for suspicious downloadFrom or webhook requests: sudo journalctl -u docker --since '24 hours ago' | grep -E '(downloadFrom|webhook|127\.0\.0\.1|::ffff)' | head -20
- Confirm patch installation after update: docker --version | grep -E '20\.(10|11)|8\.31' && echo 'Vulnerable version detected' || echo 'Update completed'
Indicators of compromise
- GET/POST requests with [::ffff:127.0.0.1] in URL parameters
- downloadFrom or webhook requests targeting internal IP ranges
- URL patterns with mixed-case protocol schemes (e.g., hTTp://, HtTp://)
- Outbound HTTP connections from Docker daemon to RFC1918 private addresses
FAQ
What is CVE-2026-42596?
CVE-2026-42596 is a critical vulnerability in Gotenberg's URL filtering mechanism that allows attackers to bypass security deny-lists using IPv6 loopback notation and case-sensitivity tricks, enabling unauthorized access to internal HTTP services from external callers.
Is CVE-2026-42596 being actively exploited?
According to CISA, CVE-2026-42596 is not currently listed as actively exploited, and no public exploits are available. However, the attack is trivial to execute and the vulnerability should be patched immediately.
What versions of Docker are affected by CVE-2026-42596?
All versions of Docker/Gotenberg prior to 8.31.0 are affected. The vulnerability exists in the default deny-list implementation of the downloadFrom and webhook features.
How do I check if my server is vulnerable to CVE-2026-42596?
Run `docker --version` and verify the version is 8.31.0 or later. Additionally, check running Gotenberg containers with `docker ps --filter 'ancestor=gotenberg'` and inspect their version tags to confirm they are not using pre-8.31.0 builds.
Does Defensia detect CVE-2026-42596?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Docker is installed on a monitored server, CVE-2026-42596 will appear in your dashboard with remediation steps.
Related Docker CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-42596. Free for 1 server.
Get started free