CVE-2026-27018High▾ TwilightGotenberg has Chromium deny-list bypass via case-insensitive URL scheme (bypass of GHSA-rh2x-ccvw-q7r3)
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.5%
0.5% → 1.7%
The fix introduced in version 8.1.0 for GHSA-rh2x-ccvw-q7r3 (CVE-2024-21527) can be bypassed using mixed-case or uppercase URL schemes.
The default --chromium-deny-list value is ^file:(?!//\/tmp/).*. This regex is anchored to lowercase file: at the start. However, per RFC 3986 Section 3.1, URI schemes are case-insensitive. Chromium normalizes the scheme to lowercase before navigation, so a URL like FILE:///etc/passwd or File:///etc/passwd bypasses the deny-list check but still gets resolved by Chromium as file:///etc/passwd.
The root cause is in pkg/gotenberg/filter.go — the FilterDeadline function compiles the deny-list regex with regexp2.MustCompile(denied.String(), 0), where 0 means no flags (case-sensitive). Since the regex pattern itself doesn't include a (?i) flag, matching is strictly case-sensitive.
This affects both the URL endpoint and HTML conversion (via iframes, link tags, etc.).
docker run --rm -p 3000:3000 gotenberg/gotenberg:8.26.0 gotenberg
/etc/passwd via the URL endpoint using an uppercase scheme:curl -X POST 'http://localhost:3000/forms/chromium/convert/url' \
--form 'url=FILE:///etc/passwd' -o output.pdf
Open output.pdf — it contains the contents of /etc/passwd.
Alternatively, create an index.html:
<iframe src="FILE:///etc/passwd" width="100%" height="100%"></iframe>
Then convert it:
curl -X POST 'http://localhost:3000/forms/chromium/convert/html' \
-F '[email protected]' -o output.pdf
/etc/passwd contents.Mixed-case variants like File:, fILE:, fiLE: etc. all work as well.
pkg/modules/chromium/chromium.go defines the default deny-list as ^file:(?!//\/tmp/).*pkg/gotenberg/filter.go compiles this with regexp2.MustCompile(denied.String(), 0) — flag 0 means case-sensitivepkg/modules/chromium/events.go uses FilterDeadline to check intercepted request URLs against the deny-listFILE:///etc/passwd becomes file:///etc/passwd after the deny-list check has already passedChange the default deny-list regex to use a case-insensitive flag:
(?i)^file:(?!//\/tmp/).*
Or apply case-insensitive matching in FilterDeadline when compiling the regex.
This is effectively the same impact as CVE-2024-21527 — unauthenticated arbitrary file read from the Gotenberg container. An attacker can leak environment variables, configuration, credentials, and other sensitive data.
github.com/gotenberg/gotenberg/v8 < 8.29.0github.com/gotenberg/gotenberg/v7 <= 7.10.2Upgrade to a patched release:
github.com/gotenberg/gotenberg/v8 8.29.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-42592Medium· 5.3Gotenberg's DNS rebinding bypasses SSRF validation on Chromium URL conversion routes
CVE-2026-42597Medium· 5.9Gotenberg allows Chromium URL conversion routes to read arbitrary files under /tmp via file:// scheme
CVE-2026-42595High· 8.6Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypass
CVE-2026-42590High· 8.2Gotenberg's ExifTool group-prefix syntax bypasses dangerous-tag blocklist
CVE-2026-40280Critical· 9.3Gotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection
CVE-2026-55229High· 7.5Gotenberg: SSRF via LibreOffice document processing