Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

gotenberg — Vulnerabilities & Security Advisories 19

All 19 CVE vulnerabilities found in gotenberg, with AI-generated Chinese analysis, references, and POCs.

This vulnerability aggregation page focuses on the open-source PDF conversion service known as gotenberg, a tool that enables server-side document processing via HTTP API. It collects and organizes security advisories specific to this product, covering a comprehensive timeline of reported flaws from its initial release through the most recently published fixes. By examining this curated collection, users can track the vendor’s response patterns over time, categorize issues by weakness type such as remote code execution or information disclosure, and review the complete historical record of vulnerabilities associated with this software. The page serves as a centralized reference for security professionals, developers, and auditors who need to assess the risk profile of deployments using gotenberg. It presents data in a structured format that highlights trends in vulnerability frequency and severity, allowing stakeholders to identify recurring failure modes within the codebase. This resource helps organizations determine when critical patches were released and evaluate whether their current version addresses known defects.

Vendor: gotenberg

CVE ID Title CVSS Severity Published
CVE-2026-44829 Gotenberg: Path traversal in zip entry name via Windows-style separators in upload filename CWE-22 8.8 High 2026-08-19
CVE-2026-45742 Gotenberg: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CWE-362 7.5 High 2026-08-19
CVE-2026-45741 Gotenberg: SSRF deny-list bypass in IsPublicIP via IPv6 6to4 / NAT64 / site-local prefixes CWE-184 7.5 High 2026-08-19
CVE-2026-55229 Gotenberg: SSRF via LibreOffice document processing CWE-918 7.5 High 2026-07-10
CVE-2026-42590 Gotenberg: ExifTool group-prefix syntax bypasses dangerous-tag blocklist CWE-184 8.2 High 2026-05-14
CVE-2026-42597 Gotenberg: Chromium URL conversion routes read arbitrary files under /tmp via file:// scheme CWE-73 5.9 Medium 2026-05-14
CVE-2026-42595 Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypass CWE-918 8.6 High 2026-05-14
CVE-2026-42594 Gotenberg: Unauthenticated denial of service via echo.Context pool reuse in webhook async goroutine CWE-362 7.5 High 2026-05-14
CVE-2026-42593 Gotenberg: Arbitrary PDF read via stampExpression and watermarkExpression in merge, split, and convert routes CWE-22 5.3 Medium 2026-05-14
CVE-2026-42592 Gotenberg: DNS rebinding bypasses SSRF validation on Chromium URL conversion routes CWE-367 5.3 Medium 2026-05-14
CVE-2026-42591 Gotenberg: Server-Side Request Forgery (SSRF) in github.com/gotenberg/gotenberg/v8 CWE-918 8.2 High 2026-05-14
CVE-2026-42596 Gotenberg: Unauthenticated SSRF via default deny-list bypass in downloadFrom and webhook CWE-918 9.4 Critical 2026-05-14
CVE-2026-40893 Gotenberg: ExifTool Dangerous Tag Blocklist Bypass via Group-Prefixed Tag Names Allows Arbitrary File Rename and Move CWE-73 8.2 High 2026-05-14
CVE-2026-42589 Gotenberg: Unauthenticated RCE via ExifTool Metadata Key Injection CWE-78 9.8 Critical 2026-05-14
CVE-2026-40281 Gotenberg vulnerable to argument injection via newlines in ExifTool metadata values CWE-88 10.0 Critical 2026-05-06
CVE-2026-39383 Gotenberg unauthenticated blind SSRF via unfiltered webhook URL CWE-918 8.2 - 2026-05-05
CVE-2026-40280 Gotenberg SSRF via case-insensitive URL scheme bypass in webhook and downloadFrom deny-lists CWE-918 5.3 - 2026-05-05
CVE-2026-35458 Gotenberg has a ReDoS via extraHttpHeaders scope feature CWE-1333 6.5AI Medium AI 2026-04-07
CVE-2026-27018 Gotenberg: Chromium deny-list bypass via case-insensitive URL scheme CWE-22 5.3 - 2026-03-30

All 19 known CVE vulnerabilities affecting gotenberg with full Chinese analysis, references, and POCs where available.