VulnSea

gotenberg has 8 CVEs on record. Disclosures have slowed: 1 in the last 90 days after 7 in the 90 before. The busiest recent month was May 2026 with 4. The median CVSS is 7.5 (high), with 1 rated critical. None have a confirmed exploitation report. Most affected products: github.com/gotenberg/gotenberg/v8 (7), gotenberg (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
Last 90 days
1 prev 7

Weakness classes

Products

  • github.com/gotenberg/gotenberg/v8 7
  • gotenberg 1
8
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

gotenberg vulnerabilities

CVEs affecting gotenberg, newest first. Open any entry for full detail, references, and exploit status.

8 CVEsRSS

CVE-2026-45741High· 7.5PoC
1mo ago

Gotenberg is a Docker-powered stateless API for PDF files

Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, the IsPublicIP function in pkg/gotenberg/outbound.go does not reject the 2002::/16 6to4 prefix, the 64:ff9b::/96 and 64:ff9b:1::/48 NAT64 prefixes, the fec…

Midnightgotenberg · gotenbergEPSS 0.76%via NVD
CVE-2026-55229High· 7.5PoC
3mo ago

Gotenberg: SSRF via LibreOffice document processing

Gotenberg: SSRF via LibreOffice document processing

Midnightgotenberg · github.com/gotenberg/gotenberg/v8EPSS 1.5%via GHSA
CVE-2026-42595High· 8.6
4mo ago

Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypass

Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypass

Twilightgotenberg · github.com/gotenberg/gotenberg/v8EPSS 0.31%via OSV
CVE-2026-42592Medium· 5.3
4mo ago

Gotenberg's DNS rebinding bypasses SSRF validation on Chromium URL conversion routes

Gotenberg's DNS rebinding bypasses SSRF validation on Chromium URL conversion routes

Sunlitgotenberg · github.com/gotenberg/gotenberg/v8EPSS 0.19%via OSV
CVE-2026-42597Medium· 5.9
4mo ago

Gotenberg allows Chromium URL conversion routes to read arbitrary files under /tmp via file:// scheme

Gotenberg allows Chromium URL conversion routes to read arbitrary files under /tmp via file:// scheme

Sunlitgotenberg · github.com/gotenberg/gotenberg/v8EPSS 0.28%via OSV
CVE-2026-42590High· 8.2
4mo ago

Gotenberg's ExifTool group-prefix syntax bypasses dangerous-tag blocklist

Gotenberg's ExifTool group-prefix syntax bypasses dangerous-tag blocklist

Twilightgotenberg · github.com/gotenberg/gotenberg/v8EPSS 0.29%via OSV
CVE-2026-40280Critical· 9.3PoC
4mo ago

Gotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection

Gotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection

Abyssalgotenberg · github.com/gotenberg/gotenberg/v8EPSS 1.9%via OSV
CVE-2026-27018High
5mo ago

Gotenberg has Chromium deny-list bypass via case-insensitive URL scheme (bypass of GHSA-rh2x-ccvw-q7r3)

Gotenberg has Chromium deny-list bypass via case-insensitive URL scheme (bypass of GHSA-rh2x-ccvw-q7r3)

Twilightgotenberg · github.com/gotenberg/gotenberg/v8EPSS 1.7%via OSV
gotenberg vulnerabilities (CVEs) · VulnSea