API Vulnerability in Gotenberg Document Converter by Gotenberg
CVE-2026-27018

7.8HIGH

Key Information:

Vendor

Gotenberg

Status
Vendor
CVE Published:
30 March 2026

What is CVE-2026-27018?

A bypass vulnerability was discovered in Gotenberg, an API for converting document formats, allowing potential exploitation through mixed-case or uppercase URL schemes. This issue affected versions prior to 8.29.0 but has been mitigated in the latest release. Users are strongly encouraged to update to version 8.29.0 to ensure protection against this vulnerability.

Affected Version(s)

gotenberg < 8.29.0

References

CVSS V4

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.