Skip to main content
CRITICAL

CVE-2026-40281

CVSS v3

10

CRITICAL

EPSS Score

2.1 %

exploit probability, as of 2026-09-30

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

Gotenberg is a Docker-powered stateless API for PDF files. In versions 8.30.1 and earlier, the metadata write endpoint validates metadata keys for control characters but leaves metadata values unsanitized. A newline character in a metadata value splits the ExifTool stdin line into two separate arguments, allowing injection of arbitrary ExifTool pseudo-tags such as -FileName, -Directory, -SymLink, and -HardLink. This is a bypass of the incomplete key-sanitization fix introduced in v8.30.1. An una

Technical details

Published
2026-05-06

Frequently asked questions

What is CVE-2026-40281?

Gotenberg is a Docker-powered stateless API for PDF files. In versions 8.30.1 and earlier, the metadata write endpoint validates metadata keys for control characters but leaves metadata values unsanitized. A newline character in a metadata value splits the ExifTool stdin line into two separate arguments, allowing injection of arbitrary ExifTool pseudo-tags such as -FileName, -Directory, -SymLink, and -HardLink. This is a bypass of the incomplete key-sanitization fix introduced in v8.30.1. An una

Is CVE-2026-40281 actively exploited?

Active exploitation of CVE-2026-40281 has not been confirmed. Its EPSS score was 2.1% on 2026-09-30, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-40281?

CVE-2026-40281 has a CVSS v3 base score of 10 (CRITICAL severity).

Is CVE-2026-40281 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key