github.com/gotenberg/gotenberg/v8 vulnerabilities
CVEs whose affected-version data names the github.com/gotenberg/gotenberg/v8 package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
7 CVEsRSS
CVE-2026-55229High· 7.5PoCGotenberg: SSRF via LibreOffice document processing
Gotenberg: SSRF via LibreOffice document processing
CVE-2026-42595High· 8.6Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypass
Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypass
CVE-2026-42592Medium· 5.3Gotenberg's DNS rebinding bypasses SSRF validation on Chromium URL conversion routes
Gotenberg's DNS rebinding bypasses SSRF validation on Chromium URL conversion routes
CVE-2026-42597Medium· 5.9Gotenberg allows Chromium URL conversion routes to read arbitrary files under /tmp via file:// scheme
Gotenberg allows Chromium URL conversion routes to read arbitrary files under /tmp via file:// scheme
CVE-2026-42590High· 8.2Gotenberg's ExifTool group-prefix syntax bypasses dangerous-tag blocklist
Gotenberg's ExifTool group-prefix syntax bypasses dangerous-tag blocklist
CVE-2026-40280Critical· 9.3PoCGotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection
Gotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection
CVE-2026-27018HighGotenberg has Chromium deny-list bypass via case-insensitive URL scheme (bypass of GHSA-rh2x-ccvw-q7r3)
Gotenberg has Chromium deny-list bypass via case-insensitive URL scheme (bypass of GHSA-rh2x-ccvw-q7r3)