Vendor
high
advisory
Gotenberg Unauthenticated SSRF Vulnerability
3 rules 1 TTPGotenberg version 8.29.1 is vulnerable to Server-Side Request Forgery (SSRF) due to an unfiltered webhook URL, allowing unauthenticated attackers to force outbound HTTP POST requests to arbitrary destinations, enabling internal network probing and interaction with internal services.
Gotenberg
ssrf
cve-2026-39383
3r
1t
critical
advisory
Gotenberg ExifTool Argument Injection via Metadata Values
2 rules 1 TTPGotenberg version 8.30.1 and earlier is vulnerable to argument injection, where an unauthenticated attacker can inject arbitrary ExifTool pseudo-tags via newline characters in metadata values, leading to arbitrary file manipulation within the container filesystem.
Gotenberg <= 8.30.1
argument-injection
vulnerability
container
2r
1t