Gotenberg
Vendor:
First CVE: Jan 7, 2021 · Active for 5 years
22
Total CVEs
More Total CVEs than 94% of tracked products
11.0
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
7.9
Avg CVSS
Higher Avg CVSS than 68% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Gotenberg over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 7, 2021
5 years ago
Most Recent CVE
May 14, 2026
71 days ago
CVE Severity & Scoring
Gotenberg22 CVEs
23%
45%
32%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network22 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (95.5%)
High1 (4.5%)
Unknown0 (0.0%)
User Interaction
None21 (95.5%)
Unknown0 (0.0%)
Required1 (4.5%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None22 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42589CRITICAL Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg's /forms/pdfengines/metadata/write HTTP endpoint accepts a JSON metadata object and passes its | May 14, 2026 | 9.8 | 50 | NO | YES |
CVE-2026-40281CRITICAL Gotenberg is a Docker-powered stateless API for PDF files. In versions 8.30.1 and earlier, the metadata write endpoint validates metadata keys for control characters but leaves met | May 6, 2026 | 9.1 | 38 | NO | NO |
CVE-2026-42596CRITICAL Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, the default deny-lists used by Gotenberg's downloadFrom feature and webhook feature are bypassable. Beca | May 14, 2026 | 9.4 | 35 | NO | NO |
CVE-2026-42595HIGH Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, Gotenberg's Chromium URL-to-PDF endpoint (/forms/chromium/convert/url) has no default protection against | May 14, 2026 | 8.6 | 32 | NO | NO |
CVE-2020-13450CRITICAL A directory traversal vulnerability in file upload function of Gotenberg through 6.2.1 allows an attacker to upload and overwrite any writable files outside the intended folder. Th | Jan 7, 2021 | 9.8 | 32 | NO | NO |
CVE-2026-42590HIGH Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.30.0, The ExifTool metadata write blocklist in Gotenberg can be bypassed using ExifTool's group-prefix syntax, | May 14, 2026 | 8.2 | 31 | NO | NO |
CVE-2026-42591HIGH Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the LibreOffice conversion endpoint (/forms/libreoffice/convert) passes uploaded documents directly to L | May 14, 2026 | 8.2 | 31 | NO | NO |
CVE-2026-40893HIGH Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg only checks if the tag is exactly FileName, so System:FileName slips right through and ExifToo | May 14, 2026 | 8.2 | 31 | NO | NO |
CVE-2026-35458CRITICAL Gotenberg is an API for converting document formats. In 8.29.1 and earlier, Gotenberg uses dlclark/regexp2 to compile user-supplied scope patterns without setting a proper timeout. | Apr 7, 2026 | 9.8 | 30 | NO | NO |
CVE-2020-13451CRITICAL An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice configuration files and execute arbitrary | Jan 7, 2021 | 9.8 | 30 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (22 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
4.5% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (22 CVEs).
Media Mentions
Signals from CVEs in this product scope (22 CVEs).
Top CNAs Publishing CVEs For Gotenberg
Top CWEs
Versions
No cataloged versions.