<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T05:10:18.844421+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-278268</id>
    <title>EUVD-2026-278268</title>
    <updated>2026-10-07T05:10:18.846542+00:00</updated>
    <content>EUVD-2026-278268</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-278268"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-27018</id>
    <title>fkie_cve-2026-27018</title>
    <updated>2026-10-07T05:10:18.846583+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Gotenberg is an API for converting document formats. Prior to version 8.29.0, the fix introduced for CVE-2024-21527 can be bypassed using mixed-case or uppercase URL schemes. This issue has been patched in version 8.29.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-27018"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jjwv-57xh-xr6r</id>
    <title>GHSA-jjwv-57xh-xr6r — Gotenberg has Chromium deny-list bypass via case-insensitive URL scheme (bypass of GHSA-rh2x-ccvw-q7r3)</title>
    <updated>2026-10-07T05:10:18.846616+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/gotenberg/gotenberg/v8, Go: github.com/gotenberg/gotenberg/v7</p>
<p>### Impact</p>
<p>The fix introduced in version 8.1.0 for GHSA-rh2x-ccvw-q7r3 (CVE-2024-21527) can be bypassed using mixed-case or uppercase URL schemes.</p>
<p>The default `--chromium-deny-list` value is `^file:(?!//\/tmp/).*`. This regex is anchored to lowercase `file:` at the start. However, per RFC 3986 Section 3.1, URI schemes are case-insensitive. Chromium normalizes the scheme to lowercase before navigation, so a URL like `FILE:///etc/passwd` or `File:///etc/passwd` bypasses the deny-list check but still gets resolved by Chromium as `file:///etc/passwd`.</p>
<p>The root cause is in `pkg/gotenberg/filter.go` — the `FilterDeadline` function compiles the deny-list regex with `regexp2.MustCompile(denied.String(), 0)`, where `0` means no flags (case-sensitive). Since the regex pattern itself doesn't include a `(?i)` flag, matching is strictly case-sensitive.</p>
<p>This affects both the URL endpoint and HTML conversion (via iframes, link tags, etc.).</p>
<p>### Steps to Reproduce</p>
<p>1. Start Gotenberg with default settings:</p>
<p>```bash
docker run --rm -p 3000:3000 gotenberg/gotenberg:8.26.0 gotenberg
```</p>
<p>2. Read `/etc/passwd` via the URL endpoint using an uppercase scheme:</p>
<p>```bash
curl -X POST 'http://localhost:3000/forms/chromium/convert/url' \
  --form 'url=FILE:///etc/passwd' -o output.pdf
```</p>
<p>3. Open `output.pdf` — it contains the contents of `/etc/passwd`.</p>
<p>4. Alternatively, create an `index.html`:</p>
<p>```html
&lt;iframe src="FILE:///etc/passwd" width="100%" height="100%"&gt;&lt;/iframe&gt;
```</p>
<p>Then convert it:…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jjwv-57xh-xr6r"/>
  </entry>
</feed>
