<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 05:10:06 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-278268</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-278268</link>
      <description>EUVD-2026-278268</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-278268</guid>
    </item>
    <item>
      <title>fkie_cve-2026-27018</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-27018</link>
      <description>&lt;p&gt;Gotenberg is an API for converting document formats. Prior to version 8.29.0, the fix introduced for CVE-2024-21527 can be bypassed using mixed-case or uppercase URL schemes. This issue has been patched in version 8.29.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Gotenberg is an API for converting document formats. Prior to version 8.29.0, the fix introduced for CVE-2024-21527 can be bypassed using mixed-case or uppercase URL schemes. This issue has been patched in version 8.29.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-27018</guid>
    </item>
    <item>
      <title>GHSA-jjwv-57xh-xr6r — Gotenberg has Chromium deny-list bypass via case-insensitive URL scheme (bypass of GHSA-rh2x-ccvw-q7r3)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jjwv-57xh-xr6r</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/gotenberg/gotenberg/v8, Go: github.com/gotenberg/gotenberg/v7&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The fix introduced in version 8.1.0 for GHSA-rh2x-ccvw-q7r3 (CVE-2024-21527) can be bypassed using mixed-case or uppercase URL schemes.&lt;/p&gt;
&lt;p&gt;The default `--chromium-deny-list` value is `^file:(?!//\/tmp/).*`. This regex is anchored to lowercase `file:` at the start. However, per RFC 3986 Section 3.1, URI schemes are case-insensitive. Chromium normalizes the scheme to lowercase before navigation, so a URL like `FILE:///etc/passwd` or `File:///etc/passwd` bypasses the deny-list check but still gets resolved by Chromium as `file:///etc/passwd`.&lt;/p&gt;
&lt;p&gt;The root cause is in `pkg/gotenberg/filter.go` — the `FilterDeadline` function compiles the deny-list regex with `regexp2.MustCompile(denied.String(), 0)`, where `0` means no flags (case-sensitive). Since the regex pattern itself doesn&amp;#39;t include a `(?i)` flag, matching is strictly case-sensitive.&lt;/p&gt;
&lt;p&gt;This affects both the URL endpoint and HTML conversion (via iframes, link tags, etc.).&lt;/p&gt;
&lt;p&gt;### Steps to Reproduce&lt;/p&gt;
&lt;p&gt;1. Start Gotenberg with default settings:&lt;/p&gt;
&lt;p&gt;```bash
docker run --rm -p 3000:3000 gotenberg/gotenberg:8.26.0 gotenberg
```&lt;/p&gt;
&lt;p&gt;2. Read `/etc/passwd` via the URL endpoint using an uppercase scheme:&lt;/p&gt;
&lt;p&gt;```bash
curl -X POST &amp;#39;http://localhost:3000/forms/chromium/convert/url&amp;#39; \
  --form &amp;#39;url=FILE:///etc/passwd&amp;#39; -o output.pdf
```&lt;/p&gt;
&lt;p&gt;3. Open `output.pdf` — it contains the contents of `/etc/passwd`.&lt;/p&gt;
&lt;p&gt;4. Alternatively, create an `index.html`:&lt;/p&gt;
&lt;p&gt;```html
&amp;lt;iframe src=&amp;#34;FILE:///etc/passwd&amp;#34; width=&amp;#34;100%&amp;#34; height=&amp;#34;100%&amp;#34;&amp;gt;&amp;lt;/iframe&amp;gt;
```&lt;/p&gt;
&lt;p&gt;Then convert it:…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/gotenberg/gotenberg/v8, Go: github.com/gotenberg/gotenberg/v7&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The fix introduced in version 8.1.0 for GHSA-rh2x-ccvw-q7r3 (CVE-2024-21527) can be bypassed using mixed-case or uppercase URL schemes.&lt;/p&gt;
&lt;p&gt;The default `--chromium-deny-list` value is `^file:(?!//\/tmp/).*`. This regex is anchored to lowercase `file:` at the start. However, per RFC 3986 Section 3.1, URI schemes are case-insensitive. Chromium normalizes the scheme to lowercase before navigation, so a URL like `FILE:///etc/passwd` or `File:///etc/passwd` bypasses the deny-list check but still gets resolved by Chromium as `file:///etc/passwd`.&lt;/p&gt;
&lt;p&gt;The root cause is in `pkg/gotenberg/filter.go` — the `FilterDeadline` function compiles the deny-list regex with `regexp2.MustCompile(denied.String(), 0)`, where `0` means no flags (case-sensitive). Since the regex pattern itself doesn&amp;#39;t include a `(?i)` flag, matching is strictly case-sensitive.&lt;/p&gt;
&lt;p&gt;This affects both the URL endpoint and HTML conversion (via iframes, link tags, etc.).&lt;/p&gt;
&lt;p&gt;### Steps to Reproduce&lt;/p&gt;
&lt;p&gt;1. Start Gotenberg with default settings:&lt;/p&gt;
&lt;p&gt;```bash
docker run --rm -p 3000:3000 gotenberg/gotenberg:8.26.0 gotenberg
```&lt;/p&gt;
&lt;p&gt;2. Read `/etc/passwd` via the URL endpoint using an uppercase scheme:&lt;/p&gt;
&lt;p&gt;```bash
curl -X POST &amp;#39;http://localhost:3000/forms/chromium/convert/url&amp;#39; \
  --form &amp;#39;url=FILE:///etc/passwd&amp;#39; -o output.pdf
```&lt;/p&gt;
&lt;p&gt;3. Open `output.pdf` — it contains the contents of `/etc/passwd`.&lt;/p&gt;
&lt;p&gt;4. Alternatively, create an `index.html`:&lt;/p&gt;
&lt;p&gt;```html
&amp;lt;iframe src=&amp;#34;FILE:///etc/passwd&amp;#34; width=&amp;#34;100%&amp;#34; height=&amp;#34;100%&amp;#34;&amp;gt;&amp;lt;/iframe&amp;gt;
```&lt;/p&gt;
&lt;p&gt;Then convert it:…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jjwv-57xh-xr6r</guid>
    </item>
  </channel>
</rss>
