{"schema_version":"1.9.0","id":"GHSA-jjwv-57xh-xr6r","published":"2026-03-30T16:16:07Z","modified":"2026-07-08T08:29:24.741570734Z","aliases":["CVE-2026-27018","GO-2026-4905"],"related":["CVE-2026-40280"],"summary":"Gotenberg has Chromium deny-list bypass via case-insensitive URL scheme (bypass of GHSA-rh2x-ccvw-q7r3)","details":"### Impact\n\nThe fix introduced in version 8.1.0 for GHSA-rh2x-ccvw-q7r3 (CVE-2024-21527) can be bypassed using mixed-case or uppercase URL schemes.\n\nThe default `--chromium-deny-list` value is `^file:(?!//\\/tmp/).*`. This regex is anchored to lowercase `file:` at the start. However, per RFC 3986 Section 3.1, URI schemes are case-insensitive. Chromium normalizes the scheme to lowercase before navigation, so a URL like `FILE:///etc/passwd` or `File:///etc/passwd` bypasses the deny-list check but still gets resolved by Chromium as `file:///etc/passwd`.\n\nThe root cause is in `pkg/gotenberg/filter.go` — the `FilterDeadline` function compiles the deny-list regex with `regexp2.MustCompile(denied.String(), 0)`, where `0` means no flags (case-sensitive). Since the regex pattern itself doesn't include a `(?i)` flag, matching is strictly case-sensitive.\n\nThis affects both the URL endpoint and HTML conversion (via iframes, link tags, etc.).\n\n### Steps to Reproduce\n\n1. Start Gotenberg with default settings:\n\n```bash\ndocker run --rm -p 3000:3000 gotenberg/gotenberg:8.26.0 gotenberg\n```\n\n2. Read `/etc/passwd` via the URL endpoint using an uppercase scheme:\n\n```bash\ncurl -X POST 'http://localhost:3000/forms/chromium/convert/url' \\\n  --form 'url=FILE:///etc/passwd' -o output.pdf\n```\n\n3. Open `output.pdf` — it contains the contents of `/etc/passwd`.\n\n4. Alternatively, create an `index.html`:\n\n```html\n<iframe src=\"FILE:///etc/passwd\" width=\"100%\" height=\"100%\"></iframe>\n```\n\nThen convert it:\n\n```bash\ncurl -X POST 'http://localhost:3000/forms/chromium/convert/html' \\\n  -F 'files=@index.html' -o output.pdf\n```\n\n5. The resulting PDF contains `/etc/passwd` contents.\n\nMixed-case variants like `File:`, `fILE:`, `fiLE:` etc. all work as well.\n\n### Root Cause\n\n- `pkg/modules/chromium/chromium.go` defines the default deny-list as `^file:(?!//\\/tmp/).*`\n- `pkg/gotenberg/filter.go` compiles this with `regexp2.MustCompile(denied.String(), 0)` — flag `0` means case-sensitive\n- `pkg/modules/chromium/events.go` uses `FilterDeadline` to check intercepted request URLs against the deny-list\n- Chromium normalizes URL schemes to lowercase, so `FILE:///etc/passwd` becomes `file:///etc/passwd` after the deny-list check has already passed\n\n### Suggested Fix\n\nChange the default deny-list regex to use a case-insensitive flag:\n\n```\n(?i)^file:(?!//\\/tmp/).*\n```\n\nOr apply case-insensitive matching in `FilterDeadline` when compiling the regex.\n\n### Severity\n\nThis is effectively the same impact as CVE-2024-21527 — unauthenticated arbitrary file read from the Gotenberg container. An attacker can leak environment variables, configuration, credentials, and other sensitive data.","affected":[{"package":{"name":"github.com/gotenberg/gotenberg/v8","ecosystem":"Go","purl":"pkg:golang/github.com/gotenberg/gotenberg/v8"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"8.29.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-jjwv-57xh-xr6r/GHSA-jjwv-57xh-xr6r.json"}},{"package":{"name":"github.com/gotenberg/gotenberg/v7","ecosystem":"Go","purl":"pkg:golang/github.com/gotenberg/gotenberg/v7"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"7.10.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-jjwv-57xh-xr6r/GHSA-jjwv-57xh-xr6r.json"}}],"references":[{"type":"WEB","url":"https://github.com/gotenberg/gotenberg/security/advisories/GHSA-jjwv-57xh-xr6r"},{"type":"WEB","url":"https://github.com/gotenberg/gotenberg/security/advisories/GHSA-rh2x-ccvw-q7r3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27018"},{"type":"WEB","url":"https://github.com/gotenberg/gotenberg/commit/06b2b2e10c52b58135edbfe82e94d599eb0c5a11"},{"type":"WEB","url":"https://github.com/gotenberg/gotenberg/commit/8625a4e899eb75e6fcf46d28394334c7fd79fff5"},{"type":"PACKAGE","url":"https://github.com/gotenberg/gotenberg"},{"type":"WEB","url":"https://github.com/gotenberg/gotenberg/releases/tag/v8.29.0"}],"database_specific":{"cwe_ids":["CWE-22","CWE-918"],"github_reviewed":true,"github_reviewed_at":"2026-03-30T16:16:07Z","nvd_published_at":"2026-03-30T21:17:08Z","severity":"HIGH"},"severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"}]}