Affected by GO-2026-4990
and 6 other vulnerabilities
GO-2026-4990: Gotenberg's DNS rebinding bypasses SSRF validation on Chromium URL conversion routes in github.com/gotenberg/gotenberg
GO-2026-5080: Gotenberg has arbitrary PDF read via stampExpression and watermarkExpression in merge, split, and convert routes in github.com/gotenberg/gotenberg
GO-2026-5162: Gotenberg has an ExifTool Dangerous Tag Blocklist Bypass via Group-Prefixed Tag Names that Allows Arbitrary File Rename and Move in github.com/gotenberg/gotenberg
GO-2026-5234: Gotenberg's ExifTool group-prefix syntax bypasses dangerous-tag blocklist in github.com/gotenberg/gotenberg
GO-2026-5244: Gotenberg has an SSRF deny-list bypass in IsPublicIP via IPv6 6to4 / NAT64 / site-local prefixes in github.com/gotenberg/gotenberg
GO-2026-5627: Gotenberg has a Server-Side Request Forgery (SSRF) Issue in github.com/gotenberg/gotenberg
GO-2026-5636: Gotenberg has Unauthenticated RCE via ExifTool Metadata Key Injection in github.com/gotenberg/gotenberg