CVE-2026-40280
Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-918
Falsificación de solicitud en servidor (SSRF)
Fecha de publicación:
05/05/2026
Última modificación:
06/05/2026
Descripción
*** Pendiente de traducción *** Gotenberg is an API-based document conversion tool. In versions 8.30.1 and earlier, the default private-IP deny-lists for the --webhook-deny-list and --api-download-from-deny-list flags use a case-sensitive regular expression (^https?://) to match URL schemes. Because Go&#39;s net/url.Parse() normalizes the scheme to lowercase before establishing the outbound TCP connection, an attacker can bypass the deny-list by simply capitalizing part of the URL scheme (e.g., HTTP://, HTTPS://, or Http://). This allows unauthenticated requests to reach internal network services, including private IP ranges, loopback addresses, and cloud instance metadata endpoints such as HTTP://169.254.169.254/latest/meta-data/. <br />
<br />
This bypasses the same security control that was patched in CVE-2026-27018.<br />
<br />
This issue has been fixed in version 8.31.0.
Impacto
Puntuación base 4.0
7.80
Gravedad 4.0
ALTA



