—
GO-2026-5151
Gotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection in github.com/gotenberg/gotenberg
Details
Gotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection in github.com/gotenberg/gotenberg
Are you affected?
Enter the version of the package you're using.
Affected packages
Go / github.com/gotenberg/gotenberg/v7
Introduced in:
0 No fixed version published yet for github.com/gotenberg/gotenberg/v7 (go modules). Pin to a known-safe version or switch to an alternative.
Go / github.com/gotenberg/gotenberg/v8
Introduced in:
0 Fixed in: 8.31.0 Fix
go get github.com/gotenberg/gotenberg/v8@v8.31.0 References
- https://github.com/gotenberg/gotenberg/security/advisories/GHSA-5q7p-7jgv-ww56 [ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-40280 [ADVISORY]
- https://github.com/advisories/GHSA-jjwv-57xh-xr6r [WEB]
- https://github.com/gotenberg/gotenberg/commit/3f01ca18d3cc21375a1e2da4b5a3f261c8548e47 [WEB]
- https://github.com/gotenberg/gotenberg/releases/tag/v8.31.0 [WEB]