Gotenberg

Thecodingmachine · 22 CVEs

CVE-2026-42590
HIGH

Gotenberg: ExifTool group-prefix syntax bypasses dangerous-tag blocklist

May 14, 2026

CVE-2026-42597
MEDIUM

Gotenberg: Chromium URL conversion routes read arbitrary files under /tmp via file:// scheme

May 14, 2026

CVE-2026-42595
HIGH

Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypass

May 14, 2026

CVE-2026-42594
HIGH

Gotenberg: Unauthenticated denial of service via echo.Context pool reuse in webhook async goroutine

May 14, 2026

CVE-2026-42593
MEDIUM

Gotenberg: Arbitrary PDF read via stampExpression and watermarkExpression in merge, split, and convert routes

May 14, 2026

CVE-2026-42592
MEDIUM

Gotenberg: DNS rebinding bypasses SSRF validation on Chromium URL conversion routes

May 14, 2026

CVE-2026-42591
HIGH

Gotenberg: Server-Side Request Forgery (SSRF) in github.com/gotenberg/gotenberg/v8

May 14, 2026

CVE-2026-42596
CRITICAL

Gotenberg: Unauthenticated SSRF via default deny-list bypass in downloadFrom and webhook

May 14, 2026

CVE-2026-40893
HIGH

Gotenberg: ExifTool Dangerous Tag Blocklist Bypass via Group-Prefixed Tag Names Allows Arbitrary File Rename and Move

May 14, 2026

CVE-2026-42589
CRITICAL

Gotenberg: Unauthenticated RCE via ExifTool Metadata Key Injection

May 14, 2026

CVE-2026-40281
CRITICAL

Gotenberg vulnerable to argument injection via newlines in ExifTool metadata values

May 6, 2026

CVE-2026-39383
MEDIUM

Gotenberg unauthenticated blind SSRF via unfiltered webhook URL

May 5, 2026

CVE-2026-40280
HIGH

Gotenberg SSRF via case-insensitive URL scheme bypass in webhook and downloadFrom deny-lists

May 5, 2026

CVE-2026-35458
HIGH

Gotenberg has a ReDoS via extraHttpHeaders scope feature

Apr 7, 2026

CVE-2026-27018
HIGH

Gotenberg: Chromium deny-list bypass via case-insensitive URL scheme

Mar 30, 2026

CVE-2020-14160
HIGH

An SSRF vulnerability in Gotenberg through 6.2.1 exists in the remote URL to PDF conversion, which results in a remote…

Aug 26, 2021

CVE-2020-14161
MEDIUM

It is possible to inject HTML and/or JavaScript in the HTML to PDF conversion in Gotenberg through 6.2.1 via the /conve…

Aug 26, 2021

CVE-2021-23345
MEDIUM

Server-side Request Forgery (SSRF)

Feb 26, 2021

CVE-2020-13449
HIGH

A directory traversal vulnerability in the Markdown engine of Gotenberg through 6.2.1 allows an attacker to read any co…

Jan 7, 2021

CVE-2020-13450
CRITICAL

A directory traversal vulnerability in file upload function of Gotenberg through 6.2.1 allows an attacker to upload and…

Jan 7, 2021

CVE-2020-13451
CRITICAL

An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to ove…

Jan 7, 2021

CVE-2020-13452
CRITICAL

In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to…

Jan 7, 2021

Showing 1 to 22 of 22 CVEs