Thecodingmachine
Thecodingmachine Gotenberg: vulnerabilidades y CVE
Thecodingmachine Gotenberg tiene 27 vulnerabilidades publicadas, 19 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE27
Últimos 12 meses19
Críticas6
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-45742 | Alta (7.5) | 0.70% | — | 19 ago 2026 | Gotenberg is a Docker-powered stateless API for PDF files. From 8.10.0 until 8.33.0, the newContext function in pkg/modules/api/context.go starts one errgroup.Go goroutine for each multipart downloadFrom entry and… |
| CVE-2026-45741 | Alta (7.5) | 0.37% | — | 19 ago 2026 | Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, the IsPublicIP function in pkg/gotenberg/outbound.go does not reject the 2002::/16 6to4 prefix, the 64:ff9b::/96 and 64:ff9b:1::/48 NAT64… |
| CVE-2026-44829 | Alta (8.8) | 0.50% | — | 19 ago 2026 | Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, filename handling in pkg/modules/api/context.go uses filepath.Base on Linux, which does not treat backslashes as path separators, so a… |
| CVE-2026-55229 | Alta (7.5) | 1.5% | — | 10 jul 2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.34.0, Gotenberg's /forms/libreoffice/convert endpoint allows a specially crafted document to cause LibreOffice to automatically retrieve external… |
| CVE-2026-42597 | Media (5.9) | 0.36% | — | 14 may 2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the /forms/chromium/convert/url and /forms/chromium/screenshot/url routes accept url=file:///tmp/... from anonymous callers. The default… |
| CVE-2026-42596 | Crítica (9.4) | 1.8% | — | 14 may 2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, the default deny-lists used by Gotenberg's downloadFrom feature and webhook feature are bypassable. Because the filter is regex-based and… |
| CVE-2026-42595 | Alta (8.6) | 0.42% | — | 14 may 2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, Gotenberg's Chromium URL-to-PDF endpoint (/forms/chromium/convert/url) has no default protection against HTTP/HTTPS-based SSRF. The default… |
| CVE-2026-42594 | Alta (7.5) | 0.38% | — | 14 may 2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the webhook middleware spawns a goroutine that holds a reference to the request's echo.Context after the synchronous handler returns… |
| CVE-2026-42593 | Media (5.3) | 0.40% | — | 14 may 2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, pdfengines/merge, pdfengines/split, libreoffice/convert, chromium/convert/url, chromium/convert/html, and chromium/convert/markdown accept… |
| CVE-2026-42592 | Media (5.3) | 0.25% | — | 14 may 2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, FilterOutboundURL resolves the hostname, checks the resolved IPs against the private-address deny-list, and returns only the error. It discards… |
| CVE-2026-42591 | Alta (8.2) | 0.35% | — | 14 may 2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the LibreOffice conversion endpoint (/forms/libreoffice/convert) passes uploaded documents directly to LibreOffice without inspecting their… |
| CVE-2026-42590 | Alta (8.2) | 0.44% | — | 14 may 2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.30.0, The ExifTool metadata write blocklist in Gotenberg can be bypassed using ExifTool's group-prefix syntax, enabling arbitrary file rename, move,… |
| CVE-2026-42589 | Crítica (9.8) | 3.7% | — | 14 may 2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg's /forms/pdfengines/metadata/write HTTP endpoint accepts a JSON metadata object and passes its keys directly to ExifTool via the… |
| CVE-2026-40893 | Alta (8.2) | 0.51% | — | 14 may 2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg only checks if the tag is exactly FileName, so System:FileName slips right through and ExifTool happily renames the file. This allows… |
| CVE-2026-40281 | Crítica (9.1) | 2.1% | — | 6 may 2026 | Gotenberg is a Docker-powered stateless API for PDF files. In versions 8.30.1 and earlier, the metadata write endpoint validates metadata keys for control characters but leaves metadata values unsanitized. A newline… |
| CVE-2026-39383 | Media (6.9) | 0.31% | — | 5 may 2026 | Gotenberg is an API-based document conversion tool. In version 8.29.1, an unauthenticated attacker with network access can force the server to make outbound HTTP POST requests to arbitrary internal or external… |
| CVE-2026-40280 | Alta (7.8) | 2.1% | — | 5 may 2026 | Gotenberg is an API-based document conversion tool. In versions 8.30.1 and earlier, the default private-IP deny-lists for the --webhook-deny-list and --api-download-from-deny-list flags use a case-sensitive regular… |
| CVE-2026-35458 | Alta (8.7) | 0.61% | — | 7 abr 2026 | Gotenberg is an API for converting document formats. In 8.29.1 and earlier, Gotenberg uses dlclark/regexp2 to compile user-supplied scope patterns without setting a proper timeout. Users with access to features using… |
| CVE-2026-27018 | Alta (7.8) | 1.6% | — | 30 mar 2026 | Gotenberg is an API for converting document formats. Prior to version 8.29.0, the fix introduced for CVE-2024-21527 can be bypassed using mixed-case or uppercase URL schemes. This issue has been patched in version… |
| CVE-2024-21527 | Alta (7.8) | 0.57% | — | 19 jul 2024 | Versions of the package github.com/gotenberg/gotenberg/v8/pkg/gotenberg before 8.1.0; versions of the package github.com/gotenberg/gotenberg/v8/pkg/modules/chromium before 8.1.0; versions of the package… |
| CVE-2020-14161 | Media (6.1) | 0.90% | — | 26 ago 2021 | It is possible to inject HTML and/or JavaScript in the HTML to PDF conversion in Gotenberg through 6.2.1 via the /convert/html endpoint. |
| CVE-2020-14160 | Alta (7.5) | 1.7% | — | 26 ago 2021 | An SSRF vulnerability in Gotenberg through 6.2.1 exists in the remote URL to PDF conversion, which results in a remote attacker being able to read local files or fetch intranet resources. |
| CVE-2021-23345 | Media (5.3) | 1.1% | — | 26 feb 2021 | All versions of package github.com/thecodingmachine/gotenberg are vulnerable to Server-side Request Forgery (SSRF) via the /convert/html endpoint when the src attribute of an HTML element refers to an internal system… |
| CVE-2020-13452 | Crítica (9.8) | 2.7% | — | 7 ene 2021 | In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file, which can lead to denial of service or code execution. |
| CVE-2020-13451 | Crítica (9.8) | 3.0% | — | 7 ene 2021 | An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice configuration files and execute arbitrary code via macros. |
| CVE-2020-13450 | Crítica (9.8) | 5.6% | — | 7 ene 2021 | A directory traversal vulnerability in file upload function of Gotenberg through 6.2.1 allows an attacker to upload and overwrite any writable files outside the intended folder. This can lead to DoS, a change to program… |
| CVE-2020-13449 | Alta (7.5) | 4.9% | — | 7 ene 2021 | A directory traversal vulnerability in the Markdown engine of Gotenberg through 6.2.1 allows an attacker to read any container files. |