Technology · Go
github.com/gotenberg/gotenberg/v8 (Go) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 22 vulnerabilities in github.com/gotenberg/gotenberg/v8 (Go): 0 in the last 7 days and 1 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-55229, was published on 10 July 2026.
- Last 7 days
- 0
- Last 90 days
- 1
- Critical, all time
- 3
- Exploited in the wild
- 0
About github.com/gotenberg/gotenberg/v8 (Go)
A Docker-powered stateless API for PDF generation from various document formats.
Latest github.com/gotenberg/gotenberg/v8 (Go) vulnerabilities
- CVE-2026-55229: Gotenberg SSRF and local file disclosure in LibreOffice conversionhighCVSS 7.5EPSS 1.5%
- GO-2026-5587 - Gotenberg has incomplete fix for ExifTool arbitrary file write: case-insensitive bypass and missing HardLink/SymLink tags…info
- CVE-2026-35458: GO-2026-5372 - Gotenberg Vulnerable to ReDoS via extraHttpHeaders scope feature in github.com/gotenberg/gotenbergmediumCVSS 4EPSS 0.6%
- CVE-2026-45742: Gotenberg race condition in multipart downloadFrom handlinghighCVSS 7.5EPSS 0.7%
- CVE-2026-45741: Gotenberg SSRF deny-list bypass in IsPublicIP via IPv6 prefixeshighCVSS 7.5EPSS 0.4%
- CVE-2026-44829: Gotenberg path traversal via Windows-style separators in ZIP entry nameshighCVSS 8.8EPSS 0.5%
- CVE-2026-42597: Gotenberg SSRF and Information Disclosure in Chromium URL routesmediumCVSS 5.9EPSS 0.4%
- CVE-2026-42596: Gotenberg SSRF via deny-list bypass in downloadFrom and webhookcriticalCVSS 9.4EPSS 1.8%
- CVE-2026-42595: Gotenberg SSRF and redirect bypass in Chromium URL-to-PDF endpointhighCVSS 8.6EPSS 0.4%
- CVE-2026-42594: Gotenberg race condition and process crash in webhook middlewarehighCVSS 7.5EPSS 0.4%
- CVE-2026-42593: Gotenberg Arbitrary PDF Read via Path Traversal in Conversion RoutesmediumCVSS 5.3EPSS 0.4%
- CVE-2026-42592: Gotenberg DNS rebinding SSRF in Chromium URL conversionmediumCVSS 5.3EPSS 0.3%
- CVE-2026-42591: Gotenberg SSRF in LibreOffice conversion endpointhighCVSS 8.2EPSS 0.4%
- CVE-2026-42590: Gotenberg ExifTool blocklist bypass via group-prefix syntaxhighCVSS 8.2EPSS 0.4%
- CVE-2026-42589: Gotenberg OS command injection in PDF metadata write endpointcriticalCVSS 9.8EPSS 3.7%
- CVE-2026-40893: Gotenberg arbitrary file manipulation via ExifTool tag bypasshighCVSS 8.2EPSS 0.5%
- CVE-2026-40281: Gotenberg argument injection in metadata write endpointcriticalCVSS 10EPSS 0.7%
- CVE-2026-39383: Gotenberg SSRF via Gotenberg-Webhook-Url headerhighCVSS 7.2EPSS 0.3%
- CVE-2026-40280: Gotenberg SSRF deny-list bypass via case-insensitive URL schemeshighCVSS 7.5EPSS 2.1%
- Gotenberg has incomplete fix for ExifTool arbitrary file write: case-insensitive bypass and missing HardLink/SymLink tagsmediumCVSS 4
- CVE-2026-27018: GO-2026-4905 - Gotenberg has Chromium deny-list bypass via case-insensitive URL scheme (bypass of GHSA-rh2x-ccvw-q7r3) in…mediumCVSS 4EPSS 1.6%
- CVE-2024-21527: GO-2024-2996 - in github.com/gotenberg/gotenberginfoEPSS 0.6%
Most severe github.com/gotenberg/gotenberg/v8 (Go) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-40281: Gotenberg argument injection in metadata write endpointcriticalCVSS 10EPSS 0.7%
- CVE-2026-42589: Gotenberg OS command injection in PDF metadata write endpointcriticalCVSS 9.8EPSS 3.7%
- CVE-2026-42596: Gotenberg SSRF via deny-list bypass in downloadFrom and webhookcriticalCVSS 9.4EPSS 1.8%
- CVE-2026-44829: Gotenberg path traversal via Windows-style separators in ZIP entry nameshighCVSS 8.8EPSS 0.5%
- CVE-2026-42595: Gotenberg SSRF and redirect bypass in Chromium URL-to-PDF endpointhighCVSS 8.6EPSS 0.4%
- CVE-2026-40893: Gotenberg arbitrary file manipulation via ExifTool tag bypasshighCVSS 8.2EPSS 0.5%
- CVE-2026-42590: Gotenberg ExifTool blocklist bypass via group-prefix syntaxhighCVSS 8.2EPSS 0.4%
- CVE-2026-42591: Gotenberg SSRF in LibreOffice conversion endpointhighCVSS 8.2EPSS 0.4%
- CVE-2026-40280: Gotenberg SSRF deny-list bypass via case-insensitive URL schemeshighCVSS 7.5EPSS 2.1%
- CVE-2026-55229: Gotenberg SSRF and local file disclosure in LibreOffice conversionhighCVSS 7.5EPSS 1.5%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 1 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/github-com-gotenberg-gotenberg-v8.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "github.com/gotenberg/gotenberg/v8 (Go) vulnerabilities", https://junglewise.ai/threats/technologies/github-com-gotenberg-gotenberg-v8, 26 September 2026.