VYPR

Gotenberg

by Gotenberg

Source repositories

CVEs (27)

  • CVE-2026-39383HigMay 5, 2026
    risk 0.40cvss 7.2epss 0.00

    Gotenberg is an API-based document conversion tool. In version 8.29.1, an unauthenticated attacker with network access can force the server to make outbound HTTP POST requests to arbitrary internal or external destinations by supplying a crafted URL in the Gotenberg-Webhook-Url…

  • CVE-2021-23345MedFeb 26, 2021
    risk 0.35cvss 5.3epss 0.01

    All versions of package github.com/thecodingmachine/gotenberg are vulnerable to Server-side Request Forgery (SSRF) via the /convert/html endpoint when the src attribute of an HTML element refers to an internal system file, such as .

  • CVE-2026-42592MedMay 14, 2026
    risk 0.34cvss 5.3epss 0.00

    Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, FilterOutboundURL resolves the hostname, checks the resolved IPs against the private-address deny-list, and returns only the error. It discards the resolved addresses. Chromium later performs its own DNS…

  • CVE-2026-42597MedMay 14, 2026
    risk 0.31cvss 5.9epss 0.00

    Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the /forms/chromium/convert/url and /forms/chromium/screenshot/url routes accept url=file:///tmp/... from anonymous callers. The default Chromium deny-list intentionally exempts file:///tmp/ so…

  • CVE-2026-42593MedMay 14, 2026
    risk 0.27cvss 5.3epss 0.00

    Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, pdfengines/merge, pdfengines/split, libreoffice/convert, chromium/convert/url, chromium/convert/html, and chromium/convert/markdown accept stampSource=pdf + stampExpression=/path and watermarkSource=pdf…

  • CVE-2020-14161MedAug 26, 2021
    risk 0.00cvss 6.1epss 0.01

    It is possible to inject HTML and/or JavaScript in the HTML to PDF conversion in Gotenberg through 6.2.1 via the /convert/html endpoint.

  • CVE-2020-14160HigAug 26, 2021
    risk 0.00cvss 7.5epss 0.02

    An SSRF vulnerability in Gotenberg through 6.2.1 exists in the remote URL to PDF conversion, which results in a remote attacker being able to read local files or fetch intranet resources.

Page 2 of 2