CVE-2026-40281
Gotenberg allows attackers to rename or overwrite files on your server.
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
Gotenberg versions prior to 8.31.0 have a critical flaw allowing unauthenticated attackers to rename, move, or overwrite files processed by the service, potentially impacting sensitive data.