CVE-2026-27018

Severity CVSS v4.0:
HIGH
Type:
CWE-22 Path Traversal
Publication date:
30/03/2026
Last modified:
29/04/2026

Description

Gotenberg is an API for converting document formats. Prior to version 8.29.0, the fix introduced for CVE-2024-21527 can be bypassed using mixed-case or uppercase URL schemes. This issue has been patched in version 8.29.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:thecodingmachine:gotenberg:*:*:*:*:*:*:*:* 8.29.0 (excluding)