PatchSiren

gotenberg CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH gotenberg CVE published 2026-08-19

CVE-2026-45742

CVE-2026-45742 is a denial-of-service vulnerability in Gotenberg, a Docker-powered stateless API for PDF files. The vulnerability exists in versions 8.10.0 through 8.32.0 and allows an unauthenticated remote attacker to crash an exposed conversion service by sending a crafted multipart request. This issue is fixed in version 8.33.0. The vulnerability is caused by the newContext function in pkg/modules/api [truncated]

HIGH gotenberg CVE published 2026-08-19

CVE-2026-45741

CVE-2026-45741 is a vulnerability in Gotenberg, a Docker-powered stateless API for PDF files. The IsPublicIP function in pkg/gotenberg/outbound.go does not correctly handle certain IPv6 prefixes, allowing an unauthenticated attacker to reach cloud metadata services. This issue is fixed in version 8.33.0. The vulnerability can be exploited in dual-stack or NAT64-enabled environments, and defenders should a [truncated]

HIGH gotenberg CVE published 2026-08-19

CVE-2026-44829

CVE-2026-44829 is a high-severity vulnerability in Gotenberg, a Docker-powered stateless API for PDF files. The issue, fixed in version 8.33.0, allows a remote attacker to write arbitrary files on a downstream Windows system when a user or process extracts a returned archive. The vulnerability arises from filename handling in pkg/modules/api/context.go, which does not properly sanitize Windows-style paren [truncated]

HIGH gotenberg CVE published 2026-05-14

CVE-2026-42595

CVE-2026-42595 documents a server-side request forgery (SSRF) vulnerability in Gotenberg, a Docker-powered stateless API for PDF generation. The vulnerability affects versions prior to 8.32.0 and was published on May 14, 2026, with a subsequent modification on May 18, 2026. The issue resides in the Chromium URL-to-PDF endpoint (/forms/chromium/convert/url), which by default lacks protection against HTTP/H [truncated]

HIGH gotenberg CVE published 2026-05-14

CVE-2026-42591

Gotenberg versions prior to 8.32.0 contain a server-side request forgery (SSRF) vulnerability in the LibreOffice conversion endpoint. The `/forms/libreoffice/convert` endpoint accepts document uploads and passes them directly to LibreOffice without content inspection. LibreOffice then independently fetches any embedded external URLs, bypassing Gotenberg's SSRF filters entirely. This allows attackers to in [truncated]

CRITICAL gotenberg CVE published 2026-05-14

CVE-2026-42589

Gotenberg versions prior to 8.31.0 contain a critical unauthenticated command injection vulnerability in the /forms/pdfengines/metadata/write endpoint. The flaw arises from insufficient validation of JSON metadata keys, which are passed directly to ExifTool via the go-exiftool library. An attacker can embed newline characters in JSON keys to split the ExifTool stdin stream, injecting arbitrary flags inclu [truncated]