SB2026040870 - Improper input validation in gotenberg



SB2026040870 - Improper input validation in gotenberg

Published: April 8, 2026

Security Bulletin ID SB2026040870
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper input validation (CVE-ID: CVE-2026-27018)

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper input validation in the chromium deny-list URL filtering logic when processing user-supplied URLs or HTML content. A remote attacker can supply a URL with a mixed-case or uppercase file scheme to disclose sensitive information.

This affects both the URL endpoint and HTML conversion via embedded resources such as iframes and link tags.


Remediation

Install update from vendor's website.