Junglewise Threat Intelligence

CVE-2026-27018: GO-2026-4905 - Gotenberg has Chromium deny-list bypass via case-insensitive URL scheme (bypass of GHSA-rh2x-ccvw-q7r3) in github.com/gotenberg/gotenberg

CVE-2026-27018 · Severity: medium · CVSS 4 · Published 2026-04-02

Technologies: github.com/gotenberg/gotenberg/v8 (Go), github.com/gotenberg/gotenberg/v7 (Go). Vendors: Go.

Executive brief

Gotenberg has Chromium deny-list bypass via case-insensitive URL scheme (bypass of GHSA-rh2x-ccvw-q7r3) in github.com/gotenberg/gotenberg

Affected products

  • Go github.com/gotenberg/gotenberg/v8
  • Go github.com/gotenberg/gotenberg/v7

Related threats