{"schema_version":1,"title":"github.com/gotenberg/gotenberg/v7 (Go) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 21 vulnerabilities in github.com/gotenberg/gotenberg/v7 (Go): 0 in the last 7 days and 1 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-55229, was published on 10 July 2026.","url":"https://junglewise.ai/threats/technologies/github-com-gotenberg-gotenberg-v7","json_url":"https://junglewise.ai/threats/technologies/github-com-gotenberg-gotenberg-v7.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/github-com-gotenberg-gotenberg-v7","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":11,"all_time":21,"critical":3,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":1,"last_365_days":20},"latest":[{"cve":"CVE-2026-55229","cvss":7.5,"epss":0.0151,"slug":"cve-2026-55229-gotenberg-ssrf-and-local-file-disclosure-in-libreoffice","title":"Gotenberg SSRF and local file disclosure in LibreOffice conversion","severity":"high","exploited":false,"published_at":"2026-07-10T21:16:55.63+00:00","url":"https://junglewise.ai/threats/cve-2026-55229-gotenberg-ssrf-and-local-file-disclosure-in-libreoffice"},{"slug":"go-2026-5587-gotenberg-has-incomplete-fix-for-exiftool-arbitrary-file-5b46f3f0","title":"GO-2026-5587 - Gotenberg has incomplete fix for ExifTool arbitrary file write: case-insensitive bypass and missing HardLink/SymLink tags in github.com/gote","severity":"info","exploited":false,"published_at":"2026-06-25T22:34:34+00:00","url":"https://junglewise.ai/threats/go-2026-5587-gotenberg-has-incomplete-fix-for-exiftool-arbitrary-file-5b46f3f0"},{"cve":"CVE-2026-35458","cvss":4,"epss":0.0061,"slug":"cve-2026-35458-gotenberg-vulnerable-to-redos-via-extrahttpheaders-scope-feature","title":"GO-2026-5372 - Gotenberg Vulnerable to ReDoS via extraHttpHeaders scope feature in github.com/gotenberg/gotenberg","severity":"medium","exploited":false,"published_at":"2026-06-25T18:43:19+00:00","url":"https://junglewise.ai/threats/cve-2026-35458-gotenberg-vulnerable-to-redos-via-extrahttpheaders-scope-feature"},{"cve":"CVE-2026-45742","cvss":7.5,"epss":0.0071,"slug":"cve-2026-45742-gotenberg-race-condition-in-multipart-downloadfrom-handling","title":"Gotenberg race condition in multipart downloadFrom handling","severity":"high","exploited":false,"published_at":"2026-05-29T16:56:18+00:00","url":"https://junglewise.ai/threats/cve-2026-45742-gotenberg-race-condition-in-multipart-downloadfrom-handling"},{"cve":"CVE-2026-45741","cvss":7.5,"epss":0.0037,"slug":"cve-2026-45741-gotenberg-ssrf-deny-list-bypass-in-ispublicip-via-ipv6-prefixes","title":"Gotenberg SSRF deny-list bypass in IsPublicIP via IPv6 prefixes","severity":"high","exploited":false,"published_at":"2026-05-29T16:50:37+00:00","url":"https://junglewise.ai/threats/cve-2026-45741-gotenberg-ssrf-deny-list-bypass-in-ispublicip-via-ipv6-prefixes"},{"cve":"CVE-2026-44829","cvss":8.8,"epss":0.005,"slug":"cve-2026-44829-gotenberg-path-traversal-via-windows-style-separators-in-zip","title":"Gotenberg path traversal via Windows-style separators in ZIP entry names","severity":"high","exploited":false,"published_at":"2026-05-29T16:38:24+00:00","url":"https://junglewise.ai/threats/cve-2026-44829-gotenberg-path-traversal-via-windows-style-separators-in-zip"},{"cve":"CVE-2026-42597","cvss":5.9,"epss":0.0036,"slug":"cve-2026-42597-gotenberg-ssrf-and-information-disclosure-in-chromium-url-routes","title":"Gotenberg SSRF and Information Disclosure in Chromium URL routes","severity":"medium","exploited":false,"published_at":"2026-05-14T16:16:23.037+00:00","url":"https://junglewise.ai/threats/cve-2026-42597-gotenberg-ssrf-and-information-disclosure-in-chromium-url-routes"},{"cve":"CVE-2026-42596","cvss":9.4,"epss":0.0177,"slug":"cve-2026-42596-gotenberg-ssrf-via-deny-list-bypass-in-downloadfrom-and-webhook","title":"Gotenberg SSRF via deny-list bypass in downloadFrom and webhook","severity":"critical","exploited":false,"published_at":"2026-05-14T16:16:22.893+00:00","url":"https://junglewise.ai/threats/cve-2026-42596-gotenberg-ssrf-via-deny-list-bypass-in-downloadfrom-and-webhook"},{"cve":"CVE-2026-42595","cvss":8.6,"epss":0.0042,"slug":"cve-2026-42595-gotenberg-ssrf-and-redirect-bypass-in-chromium-url-to-pdf","title":"Gotenberg SSRF and redirect bypass in Chromium URL-to-PDF endpoint","severity":"high","exploited":false,"published_at":"2026-05-14T16:16:22.753+00:00","url":"https://junglewise.ai/threats/cve-2026-42595-gotenberg-ssrf-and-redirect-bypass-in-chromium-url-to-pdf"},{"cve":"CVE-2026-42594","cvss":7.5,"epss":0.0038,"slug":"cve-2026-42594-gotenberg-race-condition-and-process-crash-in-webhook-middleware","title":"Gotenberg race condition and process crash in webhook middleware","severity":"high","exploited":false,"published_at":"2026-05-14T16:16:22.613+00:00","url":"https://junglewise.ai/threats/cve-2026-42594-gotenberg-race-condition-and-process-crash-in-webhook-middleware"},{"cve":"CVE-2026-42593","cvss":5.3,"epss":0.004,"slug":"cve-2026-42593-gotenberg-arbitrary-pdf-read-via-path-traversal-in-conversion","title":"Gotenberg Arbitrary PDF Read via Path Traversal in Conversion Routes","severity":"medium","exploited":false,"published_at":"2026-05-14T16:16:22.45+00:00","url":"https://junglewise.ai/threats/cve-2026-42593-gotenberg-arbitrary-pdf-read-via-path-traversal-in-conversion"},{"cve":"CVE-2026-42592","cvss":5.3,"epss":0.0025,"slug":"cve-2026-42592-gotenberg-dns-rebinding-ssrf-in-chromium-url-conversion","title":"Gotenberg DNS rebinding SSRF in Chromium URL conversion","severity":"medium","exploited":false,"published_at":"2026-05-14T16:16:22.307+00:00","url":"https://junglewise.ai/threats/cve-2026-42592-gotenberg-dns-rebinding-ssrf-in-chromium-url-conversion"},{"cve":"CVE-2026-42591","cvss":8.2,"epss":0.0035,"slug":"cve-2026-42591-gotenberg-ssrf-in-libreoffice-conversion-endpoint","title":"Gotenberg SSRF in LibreOffice conversion endpoint","severity":"high","exploited":false,"published_at":"2026-05-14T16:16:22.163+00:00","url":"https://junglewise.ai/threats/cve-2026-42591-gotenberg-ssrf-in-libreoffice-conversion-endpoint"},{"cve":"CVE-2026-42590","cvss":8.2,"epss":0.0044,"slug":"cve-2026-42590-gotenberg-exiftool-blocklist-bypass-via-group-prefix-syntax","title":"Gotenberg ExifTool blocklist bypass via group-prefix syntax","severity":"high","exploited":false,"published_at":"2026-05-14T16:16:22.01+00:00","url":"https://junglewise.ai/threats/cve-2026-42590-gotenberg-exiftool-blocklist-bypass-via-group-prefix-syntax"},{"cve":"CVE-2026-42589","cvss":9.8,"epss":0.0368,"slug":"cve-2026-42589-gotenberg-os-command-injection-in-pdf-metadata-write-endpoint","title":"Gotenberg OS command injection in PDF metadata write endpoint","severity":"critical","exploited":false,"published_at":"2026-05-14T16:16:21.867+00:00","url":"https://junglewise.ai/threats/cve-2026-42589-gotenberg-os-command-injection-in-pdf-metadata-write-endpoint"},{"cve":"CVE-2026-40893","cvss":8.2,"epss":0.0051,"slug":"cve-2026-40893-gotenberg-arbitrary-file-manipulation-via-exiftool-tag-bypass","title":"Gotenberg arbitrary file manipulation via ExifTool tag bypass","severity":"high","exploited":false,"published_at":"2026-05-14T16:16:20.323+00:00","url":"https://junglewise.ai/threats/cve-2026-40893-gotenberg-arbitrary-file-manipulation-via-exiftool-tag-bypass"},{"cve":"CVE-2026-40281","cvss":10,"epss":0.0066,"slug":"cve-2026-40281-gotenberg-argument-injection-in-metadata-write-endpoint","title":"Gotenberg argument injection in metadata write endpoint","severity":"critical","exploited":false,"published_at":"2026-05-06T21:16:01.353+00:00","url":"https://junglewise.ai/threats/cve-2026-40281-gotenberg-argument-injection-in-metadata-write-endpoint"},{"cve":"CVE-2026-39383","cvss":7.2,"epss":0.0031,"slug":"cve-2026-39383-gotenberg-ssrf-via-gotenberg-webhook-url-header","title":"Gotenberg SSRF via Gotenberg-Webhook-Url header","severity":"high","exploited":false,"published_at":"2026-05-05T21:16:22.397+00:00","url":"https://junglewise.ai/threats/cve-2026-39383-gotenberg-ssrf-via-gotenberg-webhook-url-header"},{"cve":"CVE-2026-40280","cvss":7.5,"epss":0.0212,"slug":"cve-2026-40280-gotenberg-ssrf-deny-list-bypass-via-case-insensitive-url-schemes","title":"Gotenberg SSRF deny-list bypass via case-insensitive URL schemes","severity":"high","exploited":false,"published_at":"2026-05-05T20:16:38.633+00:00","url":"https://junglewise.ai/threats/cve-2026-40280-gotenberg-ssrf-deny-list-bypass-via-case-insensitive-url-schemes"},{"cve":"CVE-2026-27018","cvss":4,"epss":0.0163,"slug":"cve-2026-27018-gotenberg-has-chromium-deny-list-bypass-via-case-insensitive-url","title":"GO-2026-4905 - Gotenberg has Chromium deny-list bypass via case-insensitive URL scheme (bypass of GHSA-rh2x-ccvw-q7r3) in github.com/gotenberg/gotenberg","severity":"medium","exploited":false,"published_at":"2026-04-02T18:42:30+00:00","url":"https://junglewise.ai/threats/cve-2026-27018-gotenberg-has-chromium-deny-list-bypass-via-case-insensitive-url"},{"cve":"CVE-2024-21527","epss":0.0057,"slug":"cve-2024-21527-go-2024-2996-in-github-com-gotenberg-gotenberg","title":"GO-2024-2996 - in github.com/gotenberg/gotenberg","severity":"info","exploited":false,"published_at":"2024-07-22T18:24:38+00:00","url":"https://junglewise.ai/threats/cve-2024-21527-go-2024-2996-in-github-com-gotenberg-gotenberg"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"github.com/mattermost/mattermost-server (Go)","slug":"github-com-mattermost-mattermost-server","vulnerabilities":274,"url":"https://junglewise.ai/threats/technologies/github-com-mattermost-mattermost-server"},{"name":"github.com/mattermost/mattermost-server/v6 (Go)","slug":"github-com-mattermost-mattermost-server-v6","vulnerabilities":188,"url":"https://junglewise.ai/threats/technologies/github-com-mattermost-mattermost-server-v6"},{"name":"github.com/mattermost/mattermost-server/v5 (Go)","slug":"github-com-mattermost-mattermost-server-v5","vulnerabilities":186,"url":"https://junglewise.ai/threats/technologies/github-com-mattermost-mattermost-server-v5"},{"name":"github.com/mattermost/mattermost/server/v8 (Go)","slug":"github-com-mattermost-mattermost-server-v8","vulnerabilities":182,"url":"https://junglewise.ai/threats/technologies/github-com-mattermost-mattermost-server-v8"},{"name":"stdlib (Go)","slug":"go-stdlib","vulnerabilities":161,"url":"https://junglewise.ai/threats/technologies/go-stdlib"},{"name":"github.com/siyuan-note/siyuan/kernel (Go)","slug":"github-com-siyuan-note-siyuan-kernel","vulnerabilities":158,"url":"https://junglewise.ai/threats/technologies/github-com-siyuan-note-siyuan-kernel"},{"name":"code.gitea.io/gitea (Go)","slug":"code-gitea-io-gitea","vulnerabilities":128,"url":"https://junglewise.ai/threats/technologies/code-gitea-io-gitea"},{"name":"gogs.io/gogs (Go)","slug":"gogs-io-gogs","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/gogs-io-gogs"},{"name":"github.com/traefik/traefik (Go)","slug":"github-com-traefik-traefik","vulnerabilities":75,"url":"https://junglewise.ai/threats/technologies/github-com-traefik-traefik"},{"name":"github.com/usememos/memos (Go)","slug":"github-com-usememos-memos","vulnerabilities":75,"url":"https://junglewise.ai/threats/technologies/github-com-usememos-memos"},{"name":"github.com/traefik/traefik/v2 (Go)","slug":"github-com-traefik-traefik-v2","vulnerabilities":73,"url":"https://junglewise.ai/threats/technologies/github-com-traefik-traefik-v2"},{"name":"github.com/traefik/traefik/v3 (Go)","slug":"github-com-traefik-traefik-v3","vulnerabilities":68,"url":"https://junglewise.ai/threats/technologies/github-com-traefik-traefik-v3"}],"technology":{"hub":true,"name":"github.com/gotenberg/gotenberg/v7 (Go)","slug":"github-com-gotenberg-gotenberg-v7","vendor":{"name":"Go","slug":"go","url":"https://junglewise.ai/threats/vendors/go"},"aliases":[],"homepage":"https://gotenberg.dev/","repo_url":"https://github.com/gotenberg/gotenberg","description":"A Go module for Gotenberg, a Docker-powered stateless API for PDF files.","url":"https://junglewise.ai/threats/technologies/github-com-gotenberg-gotenberg-v7"},"most_severe":[{"cve":"CVE-2026-40281","cvss":10,"epss":0.0066,"slug":"cve-2026-40281-gotenberg-argument-injection-in-metadata-write-endpoint","title":"Gotenberg argument injection in metadata write endpoint","severity":"critical","exploited":false,"published_at":"2026-05-06T21:16:01.353+00:00","url":"https://junglewise.ai/threats/cve-2026-40281-gotenberg-argument-injection-in-metadata-write-endpoint"},{"cve":"CVE-2026-42589","cvss":9.8,"epss":0.0368,"slug":"cve-2026-42589-gotenberg-os-command-injection-in-pdf-metadata-write-endpoint","title":"Gotenberg OS command injection in PDF metadata write endpoint","severity":"critical","exploited":false,"published_at":"2026-05-14T16:16:21.867+00:00","url":"https://junglewise.ai/threats/cve-2026-42589-gotenberg-os-command-injection-in-pdf-metadata-write-endpoint"},{"cve":"CVE-2026-42596","cvss":9.4,"epss":0.0177,"slug":"cve-2026-42596-gotenberg-ssrf-via-deny-list-bypass-in-downloadfrom-and-webhook","title":"Gotenberg SSRF via deny-list bypass in downloadFrom and webhook","severity":"critical","exploited":false,"published_at":"2026-05-14T16:16:22.893+00:00","url":"https://junglewise.ai/threats/cve-2026-42596-gotenberg-ssrf-via-deny-list-bypass-in-downloadfrom-and-webhook"},{"cve":"CVE-2026-44829","cvss":8.8,"epss":0.005,"slug":"cve-2026-44829-gotenberg-path-traversal-via-windows-style-separators-in-zip","title":"Gotenberg path traversal via Windows-style separators in ZIP entry names","severity":"high","exploited":false,"published_at":"2026-05-29T16:38:24+00:00","url":"https://junglewise.ai/threats/cve-2026-44829-gotenberg-path-traversal-via-windows-style-separators-in-zip"},{"cve":"CVE-2026-42595","cvss":8.6,"epss":0.0042,"slug":"cve-2026-42595-gotenberg-ssrf-and-redirect-bypass-in-chromium-url-to-pdf","title":"Gotenberg SSRF and redirect bypass in Chromium URL-to-PDF endpoint","severity":"high","exploited":false,"published_at":"2026-05-14T16:16:22.753+00:00","url":"https://junglewise.ai/threats/cve-2026-42595-gotenberg-ssrf-and-redirect-bypass-in-chromium-url-to-pdf"},{"cve":"CVE-2026-40893","cvss":8.2,"epss":0.0051,"slug":"cve-2026-40893-gotenberg-arbitrary-file-manipulation-via-exiftool-tag-bypass","title":"Gotenberg arbitrary file manipulation via ExifTool tag bypass","severity":"high","exploited":false,"published_at":"2026-05-14T16:16:20.323+00:00","url":"https://junglewise.ai/threats/cve-2026-40893-gotenberg-arbitrary-file-manipulation-via-exiftool-tag-bypass"},{"cve":"CVE-2026-42590","cvss":8.2,"epss":0.0044,"slug":"cve-2026-42590-gotenberg-exiftool-blocklist-bypass-via-group-prefix-syntax","title":"Gotenberg ExifTool blocklist bypass via group-prefix syntax","severity":"high","exploited":false,"published_at":"2026-05-14T16:16:22.01+00:00","url":"https://junglewise.ai/threats/cve-2026-42590-gotenberg-exiftool-blocklist-bypass-via-group-prefix-syntax"},{"cve":"CVE-2026-42591","cvss":8.2,"epss":0.0035,"slug":"cve-2026-42591-gotenberg-ssrf-in-libreoffice-conversion-endpoint","title":"Gotenberg SSRF in LibreOffice conversion endpoint","severity":"high","exploited":false,"published_at":"2026-05-14T16:16:22.163+00:00","url":"https://junglewise.ai/threats/cve-2026-42591-gotenberg-ssrf-in-libreoffice-conversion-endpoint"},{"cve":"CVE-2026-40280","cvss":7.5,"epss":0.0212,"slug":"cve-2026-40280-gotenberg-ssrf-deny-list-bypass-via-case-insensitive-url-schemes","title":"Gotenberg SSRF deny-list bypass via case-insensitive URL schemes","severity":"high","exploited":false,"published_at":"2026-05-05T20:16:38.633+00:00","url":"https://junglewise.ai/threats/cve-2026-40280-gotenberg-ssrf-deny-list-bypass-via-case-insensitive-url-schemes"},{"cve":"CVE-2026-55229","cvss":7.5,"epss":0.0151,"slug":"cve-2026-55229-gotenberg-ssrf-and-local-file-disclosure-in-libreoffice","title":"Gotenberg SSRF and local file disclosure in LibreOffice conversion","severity":"high","exploited":false,"published_at":"2026-07-10T21:16:55.63+00:00","url":"https://junglewise.ai/threats/cve-2026-55229-gotenberg-ssrf-and-local-file-disclosure-in-libreoffice"}],"generated_at":"2026-09-27T03:07:00.185062+00:00"}