Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

gotenberg — Vulnerabilities & Security Advisories 19

Browse all 19 CVE security advisories affecting gotenberg. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Gotenberg is an API for converting HTML, Markdown, and Office documents to PDF, primarily used for document processing in web applications. Historically, it has been vulnerable to remote code execution (RCE) through template injection, cross-site scripting (XSS) via malicious document content, and privilege escalation through insecure default configurations. The project has addressed multiple CVEs, including RCE flaws in template processing and XSS vulnerabilities in document rendering. While no major public security incidents have been documented, the consistent pattern of template-related RCE vulnerabilities suggests that input validation and sandboxing remain critical areas for secure deployment.

Top products by gotenberg: gotenberg
CVE ID Title CVSS Severity Published
CVE-2026-44829 Gotenberg: Path traversal in zip entry name via Windows-style separators in upload filename — gotenberg CWE-22 8.8 High 2026-08-19
CVE-2026-45742 Gotenberg: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') — gotenberg CWE-362 7.5 High 2026-08-19
CVE-2026-45741 Gotenberg: SSRF deny-list bypass in IsPublicIP via IPv6 6to4 / NAT64 / site-local prefixes — gotenberg CWE-184 7.5 High 2026-08-19
CVE-2026-55229 Gotenberg: SSRF via LibreOffice document processing — gotenberg CWE-918 7.5 High 2026-07-10
CVE-2026-42590 Gotenberg: ExifTool group-prefix syntax bypasses dangerous-tag blocklist — gotenberg CWE-184 8.2 High 2026-05-14
CVE-2026-42597 Gotenberg: Chromium URL conversion routes read arbitrary files under /tmp via file:// scheme — gotenberg CWE-73 5.9 Medium 2026-05-14
CVE-2026-42595 Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypass — gotenberg CWE-918 8.6 High 2026-05-14
CVE-2026-42594 Gotenberg: Unauthenticated denial of service via echo.Context pool reuse in webhook async goroutine — gotenberg CWE-362 7.5 High 2026-05-14
CVE-2026-42593 Gotenberg: Arbitrary PDF read via stampExpression and watermarkExpression in merge, split, and convert routes — gotenberg CWE-22 5.3 Medium 2026-05-14
CVE-2026-42592 Gotenberg: DNS rebinding bypasses SSRF validation on Chromium URL conversion routes — gotenberg CWE-367 5.3 Medium 2026-05-14
CVE-2026-42591 Gotenberg: Server-Side Request Forgery (SSRF) in github.com/gotenberg/gotenberg/v8 — gotenberg CWE-918 8.2 High 2026-05-14
CVE-2026-42596 Gotenberg: Unauthenticated SSRF via default deny-list bypass in downloadFrom and webhook — gotenberg CWE-918 9.4 Critical 2026-05-14
CVE-2026-40893 Gotenberg: ExifTool Dangerous Tag Blocklist Bypass via Group-Prefixed Tag Names Allows Arbitrary File Rename and Move — gotenberg CWE-73 8.2 High 2026-05-14
CVE-2026-42589 Gotenberg: Unauthenticated RCE via ExifTool Metadata Key Injection — gotenberg CWE-78 9.8 Critical 2026-05-14
CVE-2026-40281 Gotenberg vulnerable to argument injection via newlines in ExifTool metadata values — gotenberg CWE-88 10.0 Critical 2026-05-06
CVE-2026-39383 Gotenberg unauthenticated blind SSRF via unfiltered webhook URL — gotenberg CWE-918 8.2 - 2026-05-05
CVE-2026-40280 Gotenberg SSRF via case-insensitive URL scheme bypass in webhook and downloadFrom deny-lists — gotenberg CWE-918 5.3 - 2026-05-05
CVE-2026-35458 Gotenberg has a ReDoS via extraHttpHeaders scope feature — gotenberg CWE-1333 6.5AI Medium AI 2026-04-07
CVE-2026-27018 Gotenberg: Chromium deny-list bypass via case-insensitive URL scheme — gotenberg CWE-22 5.3 - 2026-03-30

This page lists every published CVE security advisory associated with gotenberg. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.