Description
Gotenberg is an API for converting document formats. Prior to version 8.29.0, the fix introduced for CVE-2024-21527 can be bypassed using mixed-case or uppercase URL schemes. This issue has been patched in version 8.29.0.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-jjwv-57xh-xr6r | Gotenberg has Chromium deny-list bypass via case-insensitive URL scheme (bypass of GHSA-rh2x-ccvw-q7r3) |
References
History
Tue, 31 Mar 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Gotenberg is an API for converting document formats. Prior to version 8.29.0, the fix introduced for CVE-2024-21527 can be bypassed using mixed-case or uppercase URL schemes. This issue has been patched in version 8.29.0. | |
| Title | Gotenberg: Chromium deny-list bypass via case-insensitive URL scheme | |
| Weaknesses | CWE-22 CWE-918 |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-31T14:16:20.913Z
Reserved: 2026-02-17T03:08:23.490Z
Link: CVE-2026-27018
No data.
Status : Received
Published: 2026-03-30T21:17:08.383
Modified: 2026-03-30T21:17:08.383
Link: CVE-2026-27018
No data.
OpenCVE Enrichment
No data.
Github GHSA