Vulnerability index

Browse CVEs

22 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.9 CVE-2026-42597 Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the /forms/chromium/convert/url and /forms/chromium/screenshot/url routes… Gotenberg 8.32.0+ Fix from $1,6002026-05-14 CRITICAL 9.4 CVE-2026-42596 Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, the default deny-lists used by Gotenberg's downloadFrom feature and webho… Gotenberg 8.31.0+ Fix from $2,3002026-05-14 HIGH 8.6 CVE-2026-42595 Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, Gotenberg's Chromium URL-to-PDF endpoint (/forms/chromium/convert/url) ha… Gotenberg 8.32.0+ Fix from $1,9502026-05-14 HIGH 8.2 CVE-2026-42590 Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.30.0, The ExifTool metadata write blocklist in Gotenberg can be bypassed using … Gotenberg 8.30.0+ Fix from $1,9502026-05-14 HIGH 8.2 CVE-2026-42591 Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the LibreOffice conversion endpoint (/forms/libreoffice/convert) passes u… Gotenberg 8.32.0+ Fix from $1,9502026-05-14 HIGH 7.5 CVE-2026-42594 Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the webhook middleware spawns a goroutine that holds a reference to the r… Gotenberg 8.32.0+ Fix from $1,9502026-05-14 MEDIUM 5.3 CVE-2026-42592 Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, FilterOutboundURL resolves the hostname, checks the resolved IPs against … Gotenberg 8.32.0+ Fix from $1,6002026-05-14 MEDIUM 5.3 CVE-2026-42593 Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, pdfengines/merge, pdfengines/split, libreoffice/convert, chromium/convert… Gotenberg 8.32.0+ Fix from $1,6002026-05-14 CRITICAL 9.8 CVE-2026-42589 Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg's /forms/pdfengines/metadata/write HTTP endpoint accepts a JSON… Gotenberg 8.31.0+ Fix from $2,3002026-05-14 HIGH 8.2 CVE-2026-40893 Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg only checks if the tag is exactly FileName, so System:FileName … Gotenberg 8.31.0+ Fix from $1,9502026-05-14 CRITICAL 9.1 CVE-2026-40281 Gotenberg is a Docker-powered stateless API for PDF files. In versions 8.30.1 and earlier, the metadata write endpoint validates metadata keys for co… Gotenberg 8.31.0+ Fix from $2,3002026-05-06 HIGH 7.2 CVE-2026-39383 Gotenberg is an API-based document conversion tool. In version 8.29.1, an unauthenticated attacker with network access can force the server to make o… Gotenberg 8.31.0+ Fix from $1,9502026-05-05 HIGH 7.5 CVE-2026-40280 Gotenberg is an API-based document conversion tool. In versions 8.30.1 and earlier, the default private-IP deny-lists for the --webhook-deny-list and… Gotenberg 8.31.0+ Fix from $1,9502026-05-05 CRITICAL 9.8 CVE-2026-35458 Gotenberg is an API for converting document formats. In 8.29.1 and earlier, Gotenberg uses dlclark/regexp2 to compile user-supplied scope patterns wi… Gotenberg 8.29.1+ Fix from $2,3002026-04-07 HIGH 7.5 CVE-2026-27018 Gotenberg is an API for converting document formats. Prior to version 8.29.0, the fix introduced for CVE-2024-21527 can be bypassed using mixed-case … Gotenberg 8.29.0+ Fix from $1,9502026-03-30 MEDIUM 6.1 CVE-2020-14161 It is possible to inject HTML and/or JavaScript in the HTML to PDF conversion in Gotenberg through 6.2.1 via the /convert/html endpoint. Gotenberg after 6.2.1 Fix from $1,6002021-08-26 HIGH 7.5 CVE-2020-14160 An SSRF vulnerability in Gotenberg through 6.2.1 exists in the remote URL to PDF conversion, which results in a remote attacker being able to read lo… Gotenberg after 6.2.1 Fix from $1,9502021-08-26 MEDIUM 5.3 CVE-2021-23345 All versions of package github.com/thecodingmachine/gotenberg are vulnerable to Server-side Request Forgery (SSRF) via the /convert/html endpoint whe… Gotenberg No fix yet Fix from $1,6002021-02-26 CRITICAL 9.8 CVE-2020-13452 In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file, which can… Gotenberg after 6.2.1 Fix from $2,3002021-01-07 CRITICAL 9.8 CVE-2020-13450EPSS 6% A directory traversal vulnerability in file upload function of Gotenberg through 6.2.1 allows an attacker to upload and overwrite any writable files … Gotenberg after 6.2.1 Fix from $2,3002021-01-07 CRITICAL 9.8 CVE-2020-13451 An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice configurati… Gotenberg after 6.2.1 Fix from $2,3002021-01-07 HIGH 7.5 CVE-2020-13449 A directory traversal vulnerability in the Markdown engine of Gotenberg through 6.2.1 allows an attacker to read any container files. Gotenberg after 6.2.1 Fix from $1,9502021-01-07