#VU125316 Improper input validation in gotenberg - CVE-2026-27018
Published: April 8, 2026
gotenberg
thecodingmachine
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper input validation in the chromium deny-list URL filtering logic when processing user-supplied URLs or HTML content. A remote attacker can supply a URL with a mixed-case or uppercase file scheme to disclose sensitive information.
This affects both the URL endpoint and HTML conversion via embedded resources such as iframes and link tags.