Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
25 changes: 25 additions & 0 deletions .appsec-tests/vpatch-CVE-2026-42596/CVE-2026-42596.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
## autogenerated on 2026-09-25 14:36:39
id: CVE-2026-42596
info:
name: CVE-2026-42596
author: crowdsec
severity: info
description: CVE-2026-42596 testing
tags: appsec-testing
http:
- raw:
- |
POST /forms/libreoffice/convert HTTP/1.1
Host: {{Hostname}}
Content-Type: multipart/form-data; boundary=----testBoundary

------testBoundary
Content-Disposition: form-data; name="downloadFrom"

[{"url":"http://[::ffff:127.0.0.1]:3000/health"}]
------testBoundary--
cookie-reuse: true
matchers:
- type: status
status:
- 403
5 changes: 5 additions & 0 deletions .appsec-tests/vpatch-CVE-2026-42596/config.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
## autogenerated on 2026-09-25 14:36:39
appsec-rules:
- ./appsec-rules/crowdsecurity/base-config.yaml
- ./appsec-rules/crowdsecurity/vpatch-CVE-2026-42596.yaml
nuclei_template: CVE-2026-42596.yaml
9 changes: 9 additions & 0 deletions appsec-rules/crowdsecurity/vpatch-CVE-2026-42596.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
This rule provides virtual patching for **CVE-2026-42596**, an SSRF vulnerability in **Gotenberg**, published on 2026-05-14, with a CVSS 3.1 score of **9.4 (Critical)**.

**Detection:** Detects IPv4-mapped IPv6 address SSRF attempts in Gotenberg downloadFrom requests.

Virtual patching mitigates exploitation attempts, but it does not fix the underlying vulnerability: upgrading Gotenberg to a patched version is always recommended.

### References
- [CVE-2026-42596 on NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-42596)
- [Exploit reference](https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-42596.yaml)
35 changes: 35 additions & 0 deletions appsec-rules/crowdsecurity/vpatch-CVE-2026-42596.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,35 @@
## autogenerated on 2026-09-25 14:36:39
name: crowdsecurity/vpatch-CVE-2026-42596
description: 'Detects IPv4-mapped IPv6 address SSRF attempts in Gotenberg downloadFrom requests.'
rules:
- and:
- zones:
- URI
transform:
- urldecode
- lowercase
match:
type: contains
value: '/forms/libreoffice/convert'
- zones:
- BODY_ARGS
variables:
- downloadFrom
transform:
- urldecode
- lowercase
match:
type: contains
value: '::ffff:'

labels:
type: exploit
service: http
confidence: 3
spoofable: 0
behavior: 'http:exploit'
label: 'Gotenberg - SSRF'
classification:
- cve.CVE-2026-42596
- attack.T1190
- cwe.CWE-918
1 change: 1 addition & 0 deletions collections/crowdsecurity/appsec-virtual-patching.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,7 @@ appsec-rules:
- crowdsecurity/vpatch-CVE-2023-3519
- crowdsecurity/vpatch-CVE-2023-42793
- crowdsecurity/vpatch-CVE-2025-53693
- crowdsecurity/vpatch-CVE-2026-42596
- crowdsecurity/vpatch-CVE-2023-50164
- crowdsecurity/vpatch-CVE-2023-38205
- crowdsecurity/vpatch-CVE-2023-24489
Expand Down
Loading