Package impact
Go / github.com/gotenberg/gotenberg/v8
| CVE | Severity | CVSS | Risk | Published | Description | Impact |
|---|---|---|---|---|---|---|
| CVE-2026-42589 | critical | 9.8 | 9.8 | 14d ago | Gotenberg has Unauthenticated RCE via ExifTool Metadata Key Injection | |
| CVE-2026-42596 | critical | 9.4 | 9.4 | 14d ago | Gotenberg vulnerable to unauthenticated SSRF via default deny-list bypass in downloadFrom and webhook | |
| CVE-2026-40281 | critical | 9.1 | 9.1 | 22d ago | Gotenberg has ExifTool stdin argument injection via metadata value newlines (bypass of key sanitization fix) |