SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-45741

HIGH · CVSS 7.5 EPSS 0.76% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Docker versions 8.32.0 and earlier contain a vulnerability in the IsPublicIP function of Gotenberg, which improperly handles certain IPv6 prefixes, allowing unauthenticated attackers to access internal cloud metadata services. This could lead to the exposure of sensitive cloud credentials through crafted DNS records. Organizations utilizing Docker with Gotenberg in dual-stack or NAT64 environments should prioritize upgrading to version 8.33.0 to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-45741
Severity
HIGH
CVSS
7.5
EPSS
0.76%
Docker

Original NVD Description

Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, the IsPublicIP function in pkg/gotenberg/outbound.go does not reject the 2002::/16 6to4 prefix, the 64:ff9b::/96 and 64:ff9b:1::/48 NAT64 prefixes, the fec0::/10 deprecated site-local prefix, Teredo, and other transition prefixes that can embed or route to non-public IPv4 destinations. The addr.Unmap operation only handles IPv4-mapped IPv6 addresses, so a crafted DNS AAAA record can cause the outbound HTTP client to treat an address wrapping an internal destination such as 169.254.169.254 as public. An unauthenticated attacker can use a conversion route with WithDenyPrivateIPs enabled to reach cloud metadata services, and the Chromium URL conversion route can return the internal response as a PDF, potentially exposing cloud credentials. Exploitation requires a deployment whose host routes the relevant IPv6 prefix, such as a dual-stack or NAT64-enabled environment. This issue is fixed in version 8.33.0.