Package impact

golang GO / github.com/gotenberg/gotenberg/v8

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2026-42589 critical 9.8 9.8 14d ago Gotenberg has Unauthenticated RCE via ExifTool Metadata Key Injection golang
CVE-2026-42596 critical 9.4 9.4 14d ago Gotenberg vulnerable to unauthenticated SSRF via default deny-list bypass in downloadFrom and webhook golang
CVE-2026-40281 critical 9.1 9.1 22d ago Gotenberg has ExifTool stdin argument injection via metadata value newlines (bypass of key sanitization fix) golang
CVE-2026-42595 high 8.6 8.6 14d ago Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypass golang
CVE-2026-42591 high 8.2 8.2 14d ago Gotenberg has a Server-Side Request Forgery (SSRF) Issue golang
CVE-2026-42590 high 8.2 8.2 14d ago Gotenberg's ExifTool group-prefix syntax bypasses dangerous-tag blocklist golang
CVE-2026-40893 high 8.2 8.2 14d ago Gotenberg has an ExifTool Dangerous Tag Blocklist Bypass via Group-Prefixed Tag Names that Allows Arbitrary File Rename and Move golang
CVE-2026-42594 high 7.5 7.5 14d ago Gotenberg has an unauthenticated denial of service via echo.Context pool reuse in webhook async goroutine golang
CVE-2026-40280 high 7.5 7.5 23d ago Gotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection golang
CVE-2026-39383 high 7.2 7.2 23d ago Gotenberg Vulnerable to Unauthenticated SSRF via Unfiltered Webhook URL golang
CVE-2026-42597 medium 5.9 5.9 14d ago Gotenberg allows Chromium URL conversion routes to read arbitrary files under /tmp via file:// scheme golang
CVE-2026-42593 medium 5.3 5.3 14d ago Gotenberg has arbitrary PDF read via stampExpression and watermarkExpression in merge, split, and convert routes golang
CVE-2026-42592 medium 5.3 5.3 14d ago Gotenberg's DNS rebinding bypasses SSRF validation on Chromium URL conversion routes golang