Gotenberg has an unauthenticated denial of service via echo.Context pool reuse in webhook async goroutine in github.com/gotenberg/gotenberg
Modified: 6/25/2026
package
pkg:go/github.com/gotenberg/gotenberg/v8
Gotenberg has an unauthenticated denial of service via echo.Context pool reuse in webhook async goroutine in github.com/gotenberg/gotenberg
Modified: 6/25/2026
Gotenberg has a Server-Side Request Forgery (SSRF) Issue in github.com/gotenberg/gotenberg
Modified: 6/25/2026
Gotenberg has Unauthenticated RCE via ExifTool Metadata Key Injection in github.com/gotenberg/gotenberg
Modified: 6/25/2026
Gotenberg has a Race Condition via Multipart `downloadFrom` Handling in github.com/gotenberg/gotenberg
Modified: 6/25/2026
Gotenberg: SSRF via LibreOffice document processing
Modified: 6/25/2026
Gotenberg's DNS rebinding bypasses SSRF validation on Chromium URL conversion routes
Modified: 9/10/2026
Gotenberg has arbitrary PDF read via stampExpression and watermarkExpression in merge, split, and convert routes
Modified: 6/25/2026
Gotenberg vulnerable to unauthenticated SSRF via default deny-list bypass in downloadFrom and webhook
Modified: 6/25/2026
Gotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection
Modified: 7/8/2026
Gotenberg Vulnerable to Unauthenticated SSRF via Unfiltered Webhook URL
Modified: 6/25/2026
Gotenberg has an ExifTool Dangerous Tag Blocklist Bypass via Group-Prefixed Tag Names that Allows Arbitrary File Rename and Move
Modified: 6/25/2026
Gotenberg's ExifTool group-prefix syntax bypasses dangerous-tag blocklist
Modified: 7/21/2026
Gotenberg has an SSRF deny-list bypass in IsPublicIP via IPv6 6to4 / NAT64 / site-local prefixes
Modified: 9/10/2026
Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypass
Modified: 7/21/2026
Gotenberg Vulnerable to ReDoS via extraHttpHeaders scope feature
Modified: 6/25/2026
Gotenberg allows Chromium URL conversion routes to read arbitrary files under /tmp via file:// scheme
Modified: 7/21/2026
Gotenberg has path traversal in zip entry name via Windows-style separators in upload filename
Modified: 6/25/2026
Gotenberg has Chromium deny-list bypass via case-insensitive URL scheme (bypass of GHSA-rh2x-ccvw-q7r3)
Modified: 7/8/2026
Gotenberg has ExifTool stdin argument injection via metadata value newlines (bypass of key sanitization fix)
Modified: 6/25/2026
Gotenberg has incomplete fix for ExifTool arbitrary file write: case-insensitive bypass and missing HardLink/SymLink tags
Modified: 6/25/2026
Gotenberg has an unauthenticated denial of service via echo.Context pool reuse in webhook async goroutine
Modified: 6/25/2026
Gotenberg has a Server-Side Request Forgery (SSRF) Issue
Modified: 6/25/2026
Gotenberg has Unauthenticated RCE via ExifTool Metadata Key Injection
Modified: 6/25/2026
Gotenberg has a Race Condition via Multipart `downloadFrom` Handling
Modified: 6/25/2026
CVE-2024-21527 in github.com/gotenberg/gotenberg
Modified: 3/3/2026
Gotenberg has Chromium deny-list bypass via case-insensitive URL scheme (bypass of GHSA-rh2x-ccvw-q7r3) in github.com/gotenberg/gotenberg
Modified: 4/2/2026
Gotenberg's DNS rebinding bypasses SSRF validation on Chromium URL conversion routes in github.com/gotenberg/gotenberg
Modified: 8/7/2026
Gotenberg: SSRF via LibreOffice document processing in github.com/gotenberg/gotenberg
Modified: 6/25/2026
Gotenberg has arbitrary PDF read via stampExpression and watermarkExpression in merge, split, and convert routes in github.com/gotenberg/gotenberg
Modified: 6/25/2026
Gotenberg vulnerable to unauthenticated SSRF via default deny-list bypass in downloadFrom and webhook in github.com/gotenberg/gotenberg
Modified: 6/25/2026
Gotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection in github.com/gotenberg/gotenberg
Modified: 6/25/2026
Gotenberg Vulnerable to Unauthenticated SSRF via Unfiltered Webhook URL in github.com/gotenberg/gotenberg
Modified: 6/25/2026
Gotenberg has an ExifTool Dangerous Tag Blocklist Bypass via Group-Prefixed Tag Names that Allows Arbitrary File Rename and Move in github.com/gotenberg/gotenberg
Modified: 6/25/2026
Gotenberg's ExifTool group-prefix syntax bypasses dangerous-tag blocklist in github.com/gotenberg/gotenberg
Modified: 6/25/2026
Gotenberg has an SSRF deny-list bypass in IsPublicIP via IPv6 6to4 / NAT64 / site-local prefixes in github.com/gotenberg/gotenberg
Modified: 7/2/2026
Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypass in github.com/gotenberg/gotenberg
Modified: 6/25/2026
Gotenberg Vulnerable to ReDoS via extraHttpHeaders scope feature in github.com/gotenberg/gotenberg
Modified: 6/25/2026
Gotenberg allows Chromium URL conversion routes to read arbitrary files under /tmp via file:// scheme in github.com/gotenberg/gotenberg
Modified: 6/25/2026
Gotenberg has path traversal in zip entry name via Windows-style separators in upload filename in github.com/gotenberg/gotenberg
Modified: 6/25/2026
Gotenberg has ExifTool stdin argument injection via metadata value newlines (bypass of key sanitization fix) in github.com/gotenberg/gotenberg
Modified: 6/25/2026
Gotenberg has incomplete fix for ExifTool arbitrary file write: case-insensitive bypass and missing HardLink/SymLink tags in github.com/gotenberg/gotenberg
Modified: 6/25/2026