Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-jjwv-57xh-xr6r | Gotenberg has Chromium deny-list bypass via case-insensitive URL scheme (bypass of GHSA-rh2x-ccvw-q7r3) |
Wed, 08 Apr 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Thecodingmachine
Thecodingmachine gotenberg |
|
| CPEs | cpe:2.3:a:thecodingmachine:gotenberg:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Thecodingmachine
Thecodingmachine gotenberg |
|
| Metrics |
cvssV3_1
|
Wed, 01 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gotenberg
Gotenberg gotenberg |
|
| Vendors & Products |
Gotenberg
Gotenberg gotenberg |
Tue, 31 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 31 Mar 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Gotenberg is an API for converting document formats. Prior to version 8.29.0, the fix introduced for CVE-2024-21527 can be bypassed using mixed-case or uppercase URL schemes. This issue has been patched in version 8.29.0. | |
| Title | Gotenberg: Chromium deny-list bypass via case-insensitive URL scheme | |
| Weaknesses | CWE-22 CWE-918 |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-31T14:16:20.913Z
Reserved: 2026-02-17T03:08:23.490Z
Link: CVE-2026-27018
Updated: 2026-03-31T14:16:11.237Z
Status : Analyzed
Published: 2026-03-30T21:17:08.383
Modified: 2026-04-29T01:00:01.613
Link: CVE-2026-27018
No data.
OpenCVE Enrichment
Updated: 2026-04-08T20:00:31Z
Github GHSA