Thecodingmachine maintains a narrowly focused product line centered on Gotenberg, a document-conversion and rendering service widely embedded in web applications and document-processing pipelines. The vendor's vulnerability profile skews strongly toward critical-severity outcomes, reflecting the high-value nature of a service that processes untrusted input and controls file access in production environments. Exposure recurs across a cluster of input-handling and path-manipulation weakness classes—including server-side request forgery, path traversal, external control of file names, race conditions, and incomplete input validation—that are characteristic of a service boundary exposed to user-supplied documents and rendering requests. These weakness classes concentrate on the attack surface where an attacker can influence file paths, redirect requests, or exploit timing windows in a multi-tenant or shared-resource context. Defenders should treat Gotenberg deployments as high-priority for patching and should isolate the service from untrusted input and sensitive network segments; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Thecodingmachine over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42589CRITICAL Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg's /forms/pdfengines/metadata/write HTTP endpoint accepts a JSON metadata object and passes its | May 14, 2026 | 9.8 | 50 | NO | YES |
CVE-2026-40281CRITICAL Gotenberg is a Docker-powered stateless API for PDF files. In versions 8.30.1 and earlier, the metadata write endpoint validates metadata keys for control characters but leaves met | May 6, 2026 | 9.1 | 38 | NO | NO |
CVE-2026-42596CRITICAL Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, the default deny-lists used by Gotenberg's downloadFrom feature and webhook feature are bypassable. Beca | May 14, 2026 | 9.4 | 35 | NO | NO |
CVE-2026-42595HIGH Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, Gotenberg's Chromium URL-to-PDF endpoint (/forms/chromium/convert/url) has no default protection against | May 14, 2026 | 8.6 | 32 | NO | NO |
CVE-2020-13450CRITICAL A directory traversal vulnerability in file upload function of Gotenberg through 6.2.1 allows an attacker to upload and overwrite any writable files outside the intended folder. Th | Jan 7, 2021 | 9.8 | 32 | NO | NO |
CVE-2026-42590HIGH Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.30.0, The ExifTool metadata write blocklist in Gotenberg can be bypassed using ExifTool's group-prefix syntax, | May 14, 2026 | 8.2 | 31 | NO | NO |
CVE-2026-42591HIGH Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the LibreOffice conversion endpoint (/forms/libreoffice/convert) passes uploaded documents directly to L | May 14, 2026 | 8.2 | 31 | NO | NO |
CVE-2026-40893HIGH Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg only checks if the tag is exactly FileName, so System:FileName slips right through and ExifToo | May 14, 2026 | 8.2 | 31 | NO | NO |
CVE-2026-35458CRITICAL Gotenberg is an API for converting document formats. In 8.29.1 and earlier, Gotenberg uses dlclark/regexp2 to compile user-supplied scope patterns without setting a proper timeout. | Apr 7, 2026 | 9.8 | 30 | NO | NO |
CVE-2020-13451CRITICAL An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice configuration files and execute arbitrary | Jan 7, 2021 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Thecodingmachine.
Media articles that mention a CVE ID that affects a product developed by Thecodingmachine — matched by CVE ID, not by vendor name.