gotenberg has 8 CVEs on record. Disclosures have slowed: 1 in the last 90 days after 7 in the 90 before. The busiest recent month was May 2026 with 4. The median CVSS is 7.5 (high), with 1 rated critical. None have a confirmed exploitation report. Most affected products: github.com/gotenberg/gotenberg/v8 (7), gotenberg (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 1 prev 7
Worst active — by depth score
CVE-2026-40280Critical· 9.3Gotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection64CVE-2026-55229High· 7.5Gotenberg: SSRF via LibreOffice document processing54CVE-2026-45741High· 7.5Gotenberg is a Docker-powered stateless API for PDF files53CVE-2026-42595High· 8.6Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypass47CVE-2026-42590High· 8.2Gotenberg's ExifTool group-prefix syntax bypasses dangerous-tag blocklist45
gotenberg vulnerabilities
CVEs affecting gotenberg, newest first. Open any entry for full detail, references, and exploit status.
8 CVEsRSS
CVE-2026-45741High· 7.5PoCGotenberg is a Docker-powered stateless API for PDF files
Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, the IsPublicIP function in pkg/gotenberg/outbound.go does not reject the 2002::/16 6to4 prefix, the 64:ff9b::/96 and 64:ff9b:1::/48 NAT64 prefixes, the fec…
CVE-2026-55229High· 7.5PoCGotenberg: SSRF via LibreOffice document processing
Gotenberg: SSRF via LibreOffice document processing
CVE-2026-42595High· 8.6Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypass
Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypass
CVE-2026-42592Medium· 5.3Gotenberg's DNS rebinding bypasses SSRF validation on Chromium URL conversion routes
Gotenberg's DNS rebinding bypasses SSRF validation on Chromium URL conversion routes
CVE-2026-42597Medium· 5.9Gotenberg allows Chromium URL conversion routes to read arbitrary files under /tmp via file:// scheme
Gotenberg allows Chromium URL conversion routes to read arbitrary files under /tmp via file:// scheme
CVE-2026-42590High· 8.2Gotenberg's ExifTool group-prefix syntax bypasses dangerous-tag blocklist
Gotenberg's ExifTool group-prefix syntax bypasses dangerous-tag blocklist
CVE-2026-40280Critical· 9.3PoCGotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection
Gotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection
CVE-2026-27018HighGotenberg has Chromium deny-list bypass via case-insensitive URL scheme (bypass of GHSA-rh2x-ccvw-q7r3)
Gotenberg has Chromium deny-list bypass via case-insensitive URL scheme (bypass of GHSA-rh2x-ccvw-q7r3)