Download Latest Version 8.37.0 source code.zip (2.7 MB) Google Add to Preferred Sources
Home / v8.37.0
Name Modified Size InfoDownloads / Week
Parent folder
8.37.0 source code.tar.gz 2026-09-11 2.5 MB
8.37.0 source code.zip 2026-09-11 2.7 MB
README.md 2026-09-11 4.9 kB
Totals: 3 Items   5.2 MB 4

Security Fixes ⚠️

  • Strip URL userinfo before allow-list and deny-list matching. The regexes saw the credentials, so http://trusted.example.com@10.0.0.1/ satisfied an allow-list anchored on trusted\.example\.com and skipped the IP checks, and http://a@127.0.0.1/ slipped past a deny-list anchored on 127\..
  • Treat CGNAT and benchmarking ranges as non-public. 100.64.0.0/10, where Alibaba Cloud serves instance metadata, and 198.18.0.0/15 passed the *_DENY_PRIVATE_IPS checks.
  • Reject metadata keys that collide with ExifTool options. An unprefixed key such as csv or o reached ExifTool as a command-line option, not a tag. Such keys now return 400; prefix them with a group, for example XMP:csv.
  • Validate qpdf split spans. qpdf read a span that is not a page range as another source file and appended its pages to the output. It now rejects such spans and the engine chain moves on.
  • Keep redirect verdicts generic. A downloadFrom redirect blocked by the outbound policy answered 400 with the allow-list, deny-list, or IP policy in the message. It now gets the same generic 403 as a blocked first hop.
  • Bound what a hostile page or origin can hold. Chromium's CONNECT tunnels close after 2 minutes of silence and cap at 512 in flight. downloadFrom fetches honor the request deadline, webhook deliveries get their own budget, retries included, and a remote Retry-After can no longer exceed the configured maximum wait.

New Features

  • Process a request's PDF files concurrently. --pdfengines-max-concurrency bounds how many files the per-file features (metadata, encryption, stamps, watermarks, flattening, and more) process at once, across all requests. The default 1 keeps the sequential behavior; raise it to trade memory for speed on multi-file requests. LibreOffice is not affected: scale containers instead.
  • downloadFrom limits. --api-download-from-max-concurrency bounds the fetches in flight per request, 10 by default (previously unbounded). --api-download-from-max-entries caps the array size, 0 (no limit) by default.
  • Startup warnings for risky configurations. Gotenberg now warns about allow-list patterns that match more than intended (unanchored, catch-all, or with an unterminated host), since a match skips the IP checks, and about --api-enable-debug-route without authentication. Nothing fails to start.

Bug Fixes

  • Health check failed during planned restarts (#1648). A probe between two conversions got 503 while --chromium-restart-after or --libreoffice-restart-after recycled the process. Planned restarts now report healthy; unplanned ones still don't. Thanks @adq-talbot.
  • DOCX math formulas were silently dropped (#1644). The 8.30.0 image slimming removed libreoffice-math; it's back (#1645). Thanks @joh-klein.
  • Chromium crashes hung until the request timeout (#1640). A renderer crash now fails fast with 503 (#1641). Thanks @cqjjjzr and @Haseeb-1698.
  • About 75 MB extra per Chromium browser (#1656). Recent Chromium builds preload the WebUI omnibox popup at start, headless included. Gotenberg now disables it. Thanks @carma-codebase.
  • Telemetry exported without an exporter configured (#1643). An unset OTEL_*_EXPORTER fell back to OTLP on localhost and kept retrying. Each signal now stays off until its variable is set, as documented. Thanks @SuperSandro2000.
  • Encrypted .xlsb returned 500 (#1655). It now returns 400 pointing at the password form field. Thanks @MaxFreedomPollard.
  • Uploads sharing a filename lost all but one file. Duplicates are now kept as name (2).ext, in upload order. Very long extensions and a best-effort symlink step no longer fail the request with 500.
  • Async conversions could pick up another request's Gotenberg-Output-Filename. The header is now read before Echo recycles the request context.
  • Resource leaks. Webhook callbacks answering 4xx leaked a connection, a failed LibreOffice start leaked its outbound proxy, and Chromium's per-conversion network map kept every settled request.

Chore

  • Updated Chromium to 152.0.7977.82.
  • Updated LibreOffice to 26.8.0.
  • Updated unoconverter to v0.5.0, which drops the distutils dependency.
  • Bumped Go to 1.27.1.
  • Bumped golangci-lint to v2.13.2.
  • Minor performance improvements in outbound filtering, access logging, and Chromium event handling.
  • Updated Go dependencies.
Source: README.md, updated 2026-09-11