Gotenberg is an API for converting document formats. Prior to version 8.29.0, the fix introduced for CVE-2024-21527 can be bypassed using mixed-case or uppercase URL schemes. This issue has been patched in version 8.29.0.
References
| Link | Resource |
|---|---|
| https://github.com/gotenberg/gotenberg/commit/06b2b2e10c52b58135edbfe82e94d599eb0c5a11 | Patch |
| https://github.com/gotenberg/gotenberg/commit/8625a4e899eb75e6fcf46d28394334c7fd79fff5 | Patch |
| https://github.com/gotenberg/gotenberg/releases/tag/v8.29.0 | Product Release Notes |
| https://github.com/gotenberg/gotenberg/security/advisories/GHSA-jjwv-57xh-xr6r | Exploit Mitigation Vendor Advisory |
| https://github.com/gotenberg/gotenberg/security/advisories/GHSA-jjwv-57xh-xr6r | Exploit Mitigation Vendor Advisory |
Configurations
History
08 Apr 2026, 15:57
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Thecodingmachine
Thecodingmachine gotenberg |
|
| CPE | cpe:2.3:a:thecodingmachine:gotenberg:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| References | () https://github.com/gotenberg/gotenberg/commit/06b2b2e10c52b58135edbfe82e94d599eb0c5a11 - Patch | |
| References | () https://github.com/gotenberg/gotenberg/commit/8625a4e899eb75e6fcf46d28394334c7fd79fff5 - Patch | |
| References | () https://github.com/gotenberg/gotenberg/releases/tag/v8.29.0 - Product, Release Notes | |
| References | () https://github.com/gotenberg/gotenberg/security/advisories/GHSA-jjwv-57xh-xr6r - Exploit, Mitigation, Vendor Advisory |
31 Mar 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| References | () https://github.com/gotenberg/gotenberg/security/advisories/GHSA-jjwv-57xh-xr6r - |
30 Mar 2026, 21:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-30 21:17
Updated : 2026-04-29 01:00
NVD link : CVE-2026-27018
Mitre link : CVE-2026-27018
CVE.ORG link : CVE-2026-27018
JSON object : View
Products Affected
thecodingmachine
- gotenberg
