CVE Browser

CVE-2026-42590 HIGH

Gotenberg: ExifTool group-prefix syntax bypasses dangerous-tag blocklist

CVSS 8.2 EPSS 0.44% May 14, 2026
Go
CVE-2026-42597 MEDIUM

Gotenberg: Chromium URL conversion routes read arbitrary files under /tmp via file:// scheme

CVSS 5.9 EPSS 0.36% May 14, 2026
Go
CVE-2026-42595 HIGH

Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypass

CVSS 8.6 EPSS 0.42% May 14, 2026
Go
CVE-2026-42594 HIGH

Gotenberg: Unauthenticated denial of service via echo.Context pool reuse in webhook async goroutine

CVSS 7.5 EPSS 0.38% May 14, 2026
Go
CVE-2026-42593 MEDIUM

Gotenberg: Arbitrary PDF read via stampExpression and watermarkExpression in merge, split, and convert routes

CVSS 5.3 EPSS 0.40% May 14, 2026
Go
CVE-2026-42592 MEDIUM

Gotenberg: DNS rebinding bypasses SSRF validation on Chromium URL conversion routes

CVSS 5.3 EPSS 0.25% May 14, 2026
Go
CVE-2026-42591 HIGH

Gotenberg: Server-Side Request Forgery (SSRF) in github.com/gotenberg/gotenberg/v8

CVSS 8.2 EPSS 0.35% May 14, 2026
Go
CVE-2026-42596 CRITICAL

Gotenberg: Unauthenticated SSRF via default deny-list bypass in downloadFrom and webhook

CVSS 9.4 EPSS 1.77% May 14, 2026
Go
CVE-2026-40893 HIGH

Gotenberg: ExifTool Dangerous Tag Blocklist Bypass via Group-Prefixed Tag Names Allows Arbitrary File Rename and Move

CVSS 8.2 EPSS 0.51% May 14, 2026
Go
CVE-2026-42589 CRITICAL

Gotenberg: Unauthenticated RCE via ExifTool Metadata Key Injection

CVSS 9.8 EPSS 3.67% May 14, 2026
Go
CVE-2026-40281 CRITICAL

Gotenberg vulnerable to argument injection via newlines in ExifTool metadata values

CVSS 10.0 EPSS 2.09% May 6, 2026
Go
CVE-2026-39383 MEDIUM

Gotenberg unauthenticated blind SSRF via unfiltered webhook URL

CVSS 6.9 EPSS 0.31% May 5, 2026
Go
CVE-2026-40280 HIGH

Gotenberg SSRF via case-insensitive URL scheme bypass in webhook and downloadFrom deny-lists

CVSS 7.8 EPSS 2.11% May 5, 2026
Go
CVE-2026-35458 HIGH

Gotenberg has a ReDoS via extraHttpHeaders scope feature

CVSS 8.7 EPSS 0.61% Apr 7, 2026
Go
CVE-2026-27018 HIGH

Gotenberg: Chromium deny-list bypass via case-insensitive URL scheme

CVSS 7.8 EPSS 1.63% Mar 30, 2026
Go
CVE-2020-14160 HIGH

An SSRF vulnerability in Gotenberg through 6.2.1 exists in the remote URL to PDF conversion, which results in a remote attacker being able to read local files…

CVSS 7.5 EPSS 1.70% Aug 26, 2021
CVE-2020-14161 MEDIUM

It is possible to inject HTML and/or JavaScript in the HTML to PDF conversion in Gotenberg through 6.2.1 via the /convert/html endpoint.

CVSS 6.1 EPSS 0.90% Aug 26, 2021
CVE-2021-23345 MEDIUM

Server-side Request Forgery (SSRF)

CVSS 5.3 EPSS 1.09% Feb 26, 2021
CVE-2020-13449 HIGH

A directory traversal vulnerability in the Markdown engine of Gotenberg through 6.2.1 allows an attacker to read any container files.

CVSS 7.5 EPSS 5.00% Jan 7, 2021
CVE-2020-13450 CRITICAL

A directory traversal vulnerability in file upload function of Gotenberg through 6.2.1 allows an attacker to upload and overwrite any writable files outside th…

CVSS 9.8 EPSS 5.83% Jan 7, 2021
CVE-2020-13451 CRITICAL

An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice configuration files a…

CVSS 9.8 EPSS 3.15% Jan 7, 2021
CVE-2020-13452 CRITICAL

In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file, which can lead to d…

CVSS 9.8 EPSS 2.86% Jan 7, 2021

Showing 1 to 22 CVEs · page 1