CVE Browser
Gotenberg: ExifTool group-prefix syntax bypasses dangerous-tag blocklist
Gotenberg: Chromium URL conversion routes read arbitrary files under /tmp via file:// scheme
Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypass
Gotenberg: Unauthenticated denial of service via echo.Context pool reuse in webhook async goroutine
Gotenberg: Arbitrary PDF read via stampExpression and watermarkExpression in merge, split, and convert routes
Gotenberg: DNS rebinding bypasses SSRF validation on Chromium URL conversion routes
Gotenberg: Server-Side Request Forgery (SSRF) in github.com/gotenberg/gotenberg/v8
Gotenberg: Unauthenticated SSRF via default deny-list bypass in downloadFrom and webhook
Gotenberg: ExifTool Dangerous Tag Blocklist Bypass via Group-Prefixed Tag Names Allows Arbitrary File Rename and Move
Gotenberg: Unauthenticated RCE via ExifTool Metadata Key Injection
Gotenberg vulnerable to argument injection via newlines in ExifTool metadata values
Gotenberg unauthenticated blind SSRF via unfiltered webhook URL
Gotenberg SSRF via case-insensitive URL scheme bypass in webhook and downloadFrom deny-lists
Gotenberg has a ReDoS via extraHttpHeaders scope feature
Gotenberg: Chromium deny-list bypass via case-insensitive URL scheme
An SSRF vulnerability in Gotenberg through 6.2.1 exists in the remote URL to PDF conversion, which results in a remote attacker being able to read local files…
It is possible to inject HTML and/or JavaScript in the HTML to PDF conversion in Gotenberg through 6.2.1 via the /convert/html endpoint.
Server-side Request Forgery (SSRF)
A directory traversal vulnerability in the Markdown engine of Gotenberg through 6.2.1 allows an attacker to read any container files.
A directory traversal vulnerability in file upload function of Gotenberg through 6.2.1 allows an attacker to upload and overwrite any writable files outside th…
An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice configuration files a…
In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file, which can lead to d…
Showing 1 to 22 CVEs · page 1