This bypasses the same security control that was patched in CVE-2026-27018.
This issue has been fixed in version 8.31.0.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-5q7p-7jgv-ww56 | Gotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection |
Fri, 08 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Thecodingmachine
Thecodingmachine gotenberg |
|
| CPEs | cpe:2.3:a:thecodingmachine:gotenberg:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Thecodingmachine
Thecodingmachine gotenberg |
|
| Metrics |
cvssV3_1
|
Wed, 06 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 05 May 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gotenberg
Gotenberg gotenberg |
|
| Vendors & Products |
Gotenberg
Gotenberg gotenberg |
Tue, 05 May 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Gotenberg is an API-based document conversion tool. In versions 8.30.1 and earlier, the default private-IP deny-lists for the --webhook-deny-list and --api-download-from-deny-list flags use a case-sensitive regular expression (^https?://) to match URL schemes. Because Go's net/url.Parse() normalizes the scheme to lowercase before establishing the outbound TCP connection, an attacker can bypass the deny-list by simply capitalizing part of the URL scheme (e.g., HTTP://, HTTPS://, or Http://). This allows unauthenticated requests to reach internal network services, including private IP ranges, loopback addresses, and cloud instance metadata endpoints such as HTTP://169.254.169.254/latest/meta-data/. This bypasses the same security control that was patched in CVE-2026-27018. This issue has been fixed in version 8.31.0. | |
| Title | Gotenberg SSRF via case-insensitive URL scheme bypass in webhook and downloadFrom deny-lists | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-06T18:41:51.071Z
Reserved: 2026-04-10T20:22:44.034Z
Link: CVE-2026-40280
Updated: 2026-05-06T18:41:29.962Z
Status : Analyzed
Published: 2026-05-05T20:16:38.633
Modified: 2026-05-08T19:06:45.047
Link: CVE-2026-40280
No data.
OpenCVE Enrichment
Updated: 2026-05-05T23:00:10Z
Github GHSA