VendorsTheCodingMachinegotenbergall versions
Vulnerabilities

TheCodingMachine Gotenberg

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

22CVEs
CVE-2026-40281
Gotenberg vulnerable to argument injection via newlines in ExifTool metadata values
Published 2026-05-06 · Analyzed
10.0EPSS 0.006
CVE-2020-13450
A directory traversal vulnerability in file upload function of Gotenberg through 6.2.1 allows an attacker to upload and overwrite any writable files outside the intended folder. This can lead to DoS, a change to program behavior, or code execution.
Published 2021-01-07 · Modified
9.8EPSS 0.056
CVE-2020-13451
An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice configuration files and execute arbitrary code via macros.
Published 2021-01-07 · Modified
9.8EPSS 0.030
CVE-2026-42589
Gotenberg: Unauthenticated RCE via ExifTool Metadata Key Injection
Published 2026-05-14 · Analyzed
9.8EPSS 0.030
CVE-2020-13452
In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file, which can lead to denial of service or code execution.
Published 2021-01-07 · Modified
9.8EPSS 0.027
CVE-2026-35458
Gotenberg has a ReDoS via extraHttpHeaders scope feature
Published 2026-04-07 · Analyzed
9.8EPSS 0.005
CVE-2026-42596
Gotenberg: Unauthenticated SSRF via default deny-list bypass in downloadFrom and webhook
Published 2026-05-14 · Analyzed
9.4EPSS 0.012
CVE-2026-42595
Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypass
Published 2026-05-14 · Analyzed
8.6EPSS 0.003
CVE-2026-40893
Gotenberg: ExifTool Dangerous Tag Blocklist Bypass via Group-Prefixed Tag Names Allows Arbitrary File Rename and Move
Published 2026-05-14 · Analyzed
8.2EPSS 0.003
CVE-2026-42590
Gotenberg: ExifTool group-prefix syntax bypasses dangerous-tag blocklist
Published 2026-05-14 · Analyzed
8.2EPSS 0.003
CVE-2026-42591
Gotenberg: Server-Side Request Forgery (SSRF) in github.com/gotenberg/gotenberg/v8
Published 2026-05-14 · Analyzed
8.2EPSS 0.003
CVE-2026-40280
Gotenberg SSRF via case-insensitive URL scheme bypass in webhook and downloadFrom deny-lists
Published 2026-05-05 · Analyzed
7.8EPSS 0.020
CVE-2026-27018
Gotenberg: Chromium deny-list bypass via case-insensitive URL scheme
Published 2026-03-30 · Analyzed
7.8EPSS 0.017
CVE-2020-13449
A directory traversal vulnerability in the Markdown engine of Gotenberg through 6.2.1 allows an attacker to read any container files.
Published 2021-01-07 · Modified
7.5EPSS 0.049
CVE-2020-14160
An SSRF vulnerability in Gotenberg through 6.2.1 exists in the remote URL to PDF conversion, which results in a remote attacker being able to read local files or fetch intranet resources.
Published 2021-08-26 · Modified
7.5EPSS 0.017
CVE-2026-42594
Gotenberg: Unauthenticated denial of service via echo.Context pool reuse in webhook async goroutine
Published 2026-05-14 · Analyzed
7.5EPSS 0.003
CVE-2026-39383
Gotenberg unauthenticated blind SSRF via unfiltered webhook URL
Published 2026-05-05 · Analyzed
7.2EPSS 0.002
CVE-2020-14161
It is possible to inject HTML and/or JavaScript in the HTML to PDF conversion in Gotenberg through 6.2.1 via the /convert/html endpoint.
Published 2021-08-26 · Modified
6.1EPSS 0.009
CVE-2026-42597
Gotenberg: Chromium URL conversion routes read arbitrary files under /tmp via file:// scheme
Published 2026-05-14 · Analyzed
5.9EPSS 0.003
CVE-2021-23345
Server-side Request Forgery (SSRF)
Published 2021-02-26 · Modified
5.3EPSS 0.011
CVE-2026-42593
Gotenberg: Arbitrary PDF read via stampExpression and watermarkExpression in merge, split, and convert routes
Published 2026-05-14 · Analyzed
5.3EPSS 0.003
CVE-2026-42592
Gotenberg: DNS rebinding bypasses SSRF validation on Chromium URL conversion routes
Published 2026-05-14 · Analyzed
5.3EPSS 0.002