Improper input validation in gotenberg - CVE-2026-27018

 

Improper input validation in gotenberg - CVE-2026-27018

Published: April 8, 2026


Vulnerability identifier: #VU125316
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-27018
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper input validation in the chromium deny-list URL filtering logic when processing user-supplied URLs or HTML content. A remote attacker can supply a URL with a mixed-case or uppercase file scheme to disclose sensitive information.

This affects both the URL endpoint and HTML conversion via embedded resources such as iframes and link tags.


Affected software

gotenberg

How to mitigate CVE-2026-27018

Install security update from vendor's website.

gotenberg - update to 8.29.0

External References

Related Security Bulletins