Gotenberg
Thecodingmachine · 22 CVEs
Gotenberg: ExifTool group-prefix syntax bypasses dangerous-tag blocklist
May 14, 2026
Gotenberg: Chromium URL conversion routes read arbitrary files under /tmp via file:// scheme
May 14, 2026
Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypass
May 14, 2026
Gotenberg: Unauthenticated denial of service via echo.Context pool reuse in webhook async goroutine
May 14, 2026
Gotenberg: Arbitrary PDF read via stampExpression and watermarkExpression in merge, split, and convert routes
May 14, 2026
Gotenberg: DNS rebinding bypasses SSRF validation on Chromium URL conversion routes
May 14, 2026
Gotenberg: Server-Side Request Forgery (SSRF) in github.com/gotenberg/gotenberg/v8
May 14, 2026
Gotenberg: Unauthenticated SSRF via default deny-list bypass in downloadFrom and webhook
May 14, 2026
Gotenberg: ExifTool Dangerous Tag Blocklist Bypass via Group-Prefixed Tag Names Allows Arbitrary File Rename and Move
May 14, 2026
Gotenberg: Unauthenticated RCE via ExifTool Metadata Key Injection
May 14, 2026
Gotenberg vulnerable to argument injection via newlines in ExifTool metadata values
May 6, 2026
Gotenberg unauthenticated blind SSRF via unfiltered webhook URL
May 5, 2026
Gotenberg SSRF via case-insensitive URL scheme bypass in webhook and downloadFrom deny-lists
May 5, 2026
Gotenberg has a ReDoS via extraHttpHeaders scope feature
Apr 7, 2026
Gotenberg: Chromium deny-list bypass via case-insensitive URL scheme
Mar 30, 2026
An SSRF vulnerability in Gotenberg through 6.2.1 exists in the remote URL to PDF conversion, which results in a remote…
Aug 26, 2021
It is possible to inject HTML and/or JavaScript in the HTML to PDF conversion in Gotenberg through 6.2.1 via the /conve…
Aug 26, 2021
Server-side Request Forgery (SSRF)
Feb 26, 2021
A directory traversal vulnerability in the Markdown engine of Gotenberg through 6.2.1 allows an attacker to read any co…
Jan 7, 2021
A directory traversal vulnerability in file upload function of Gotenberg through 6.2.1 allows an attacker to upload and…
Jan 7, 2021
An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to ove…
Jan 7, 2021
In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to…
Jan 7, 2021
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-42590 | Gotenberg: ExifTool group-prefix syntax bypasses dangerous-tag blocklist | HIGH | 0.44% | May 14, 2026 |
| CVE-2026-42597 | Gotenberg: Chromium URL conversion routes read arbitrary files under /tmp via file:// scheme | MEDIUM | 0.36% | May 14, 2026 |
| CVE-2026-42595 | Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypass | HIGH | 0.42% | May 14, 2026 |
| CVE-2026-42594 | Gotenberg: Unauthenticated denial of service via echo.Context pool reuse in webhook async goroutine | HIGH | 0.38% | May 14, 2026 |
| CVE-2026-42593 | Gotenberg: Arbitrary PDF read via stampExpression and watermarkExpression in merge, split, and convert routes | MEDIUM | 0.40% | May 14, 2026 |
| CVE-2026-42592 | Gotenberg: DNS rebinding bypasses SSRF validation on Chromium URL conversion routes | MEDIUM | 0.25% | May 14, 2026 |
| CVE-2026-42591 | Gotenberg: Server-Side Request Forgery (SSRF) in github.com/gotenberg/gotenberg/v8 | HIGH | 0.35% | May 14, 2026 |
| CVE-2026-42596 | Gotenberg: Unauthenticated SSRF via default deny-list bypass in downloadFrom and webhook | CRITICAL | 1.77% | May 14, 2026 |
| CVE-2026-40893 | Gotenberg: ExifTool Dangerous Tag Blocklist Bypass via Group-Prefixed Tag Names Allows Arbitrary File Rename and Move | HIGH | 0.51% | May 14, 2026 |
| CVE-2026-42589 | Gotenberg: Unauthenticated RCE via ExifTool Metadata Key Injection | CRITICAL | 3.67% | May 14, 2026 |
| CVE-2026-40281 | Gotenberg vulnerable to argument injection via newlines in ExifTool metadata values | CRITICAL | 2.09% | May 6, 2026 |
| CVE-2026-39383 | Gotenberg unauthenticated blind SSRF via unfiltered webhook URL | MEDIUM | 0.31% | May 5, 2026 |
| CVE-2026-40280 | Gotenberg SSRF via case-insensitive URL scheme bypass in webhook and downloadFrom deny-lists | HIGH | 2.11% | May 5, 2026 |
| CVE-2026-35458 | Gotenberg has a ReDoS via extraHttpHeaders scope feature | HIGH | 0.61% | Apr 7, 2026 |
| CVE-2026-27018 | Gotenberg: Chromium deny-list bypass via case-insensitive URL scheme | HIGH | 1.63% | Mar 30, 2026 |
| CVE-2020-14160 | An SSRF vulnerability in Gotenberg through 6.2.1 exists in the remote URL to PDF conversion, which results in a remote attacker being able to read local files… | HIGH | 1.70% | Aug 26, 2021 |
| CVE-2020-14161 | It is possible to inject HTML and/or JavaScript in the HTML to PDF conversion in Gotenberg through 6.2.1 via the /convert/html endpoint. | MEDIUM | 0.90% | Aug 26, 2021 |
| CVE-2021-23345 | Server-side Request Forgery (SSRF) | MEDIUM | 1.09% | Feb 26, 2021 |
| CVE-2020-13449 | A directory traversal vulnerability in the Markdown engine of Gotenberg through 6.2.1 allows an attacker to read any container files. | HIGH | 5.00% | Jan 7, 2021 |
| CVE-2020-13450 | A directory traversal vulnerability in file upload function of Gotenberg through 6.2.1 allows an attacker to upload and overwrite any writable files outside th… | CRITICAL | 5.83% | Jan 7, 2021 |
| CVE-2020-13451 | An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice configuration files a… | CRITICAL | 3.15% | Jan 7, 2021 |
| CVE-2020-13452 | In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file, which can lead to d… | CRITICAL | 2.86% | Jan 7, 2021 |
Showing 1 to 22 of 22 CVEs