Thecodingmachine

Gotenberg

22 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.29%
  • Veröffentlicht 14.05.2026 15:36:30
  • Zuletzt bearbeitet 18.05.2026 12:15:42

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.30.0, The ExifTool metadata write blocklist in Gotenberg can be bypassed using ExifTool's group-prefix syntax, enabling arbitrary file rename, move, hardlink, and symlink creation ...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 14.05.2026 15:34:06
  • Zuletzt bearbeitet 18.05.2026 13:02:08

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the /forms/chromium/convert/url and /forms/chromium/screenshot/url routes accept url=file:///tmp/... from anonymous callers. The default Chromium deny-list intentionally exem...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 14.05.2026 15:33:29
  • Zuletzt bearbeitet 18.05.2026 13:01:44

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, Gotenberg's Chromium URL-to-PDF endpoint (/forms/chromium/convert/url) has no default protection against HTTP/HTTPS-based SSRF. The default deny-list regex only blocks file:/...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 14.05.2026 15:32:32
  • Zuletzt bearbeitet 18.05.2026 13:02:23

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the webhook middleware spawns a goroutine that holds a reference to the request's echo.Context after the synchronous handler returns ErrAsyncProcess and Echo recycles the con...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 14.05.2026 15:31:27
  • Zuletzt bearbeitet 18.05.2026 13:01:49

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, pdfengines/merge, pdfengines/split, libreoffice/convert, chromium/convert/url, chromium/convert/html, and chromium/convert/markdown accept stampSource=pdf + stampExpression=/...

Exploit
  • EPSS 0.19%
  • Veröffentlicht 14.05.2026 15:30:34
  • Zuletzt bearbeitet 18.05.2026 13:02:01

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, FilterOutboundURL resolves the hostname, checks the resolved IPs against the private-address deny-list, and returns only the error. It discards the resolved addresses. Chromi...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 14.05.2026 15:20:43
  • Zuletzt bearbeitet 18.05.2026 13:02:13

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the LibreOffice conversion endpoint (/forms/libreoffice/convert) passes uploaded documents directly to LibreOffice without inspecting their content. LibreOffice then fetches ...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 14.05.2026 15:19:34
  • Zuletzt bearbeitet 18.05.2026 12:16:20

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, the default deny-lists used by Gotenberg's downloadFrom feature and webhook feature are bypassable. Because the filter is regex-based and case-sensitive, an unauthenticated a...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 14.05.2026 15:18:27
  • Zuletzt bearbeitet 18.05.2026 13:02:17

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg only checks if the tag is exactly FileName, so System:FileName slips right through and ExifTool happily renames the file. This allows remote attackers to move, rena...

Exploit
  • EPSS 2.95%
  • Veröffentlicht 14.05.2026 15:11:30
  • Zuletzt bearbeitet 18.05.2026 13:01:53

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg's /forms/pdfengines/metadata/write HTTP endpoint accepts a JSON metadata object and passes its keys directly to ExifTool via the go-exiftool library. No validation ...