#VU125316 Improper input validation in gotenberg - CVE-2026-27018

 

#VU125316 Improper input validation in gotenberg - CVE-2026-27018

Published: April 8, 2026


Vulnerability identifier: #VU125316
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2026-27018
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
gotenberg
Software vendor:
thecodingmachine

Description

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper input validation in the chromium deny-list URL filtering logic when processing user-supplied URLs or HTML content. A remote attacker can supply a URL with a mixed-case or uppercase file scheme to disclose sensitive information.

This affects both the URL endpoint and HTML conversion via embedded resources such as iframes and link tags.


Remediation

Install security update from vendor's website.

External links