<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 07:03:34 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-318572</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-318572</link>
      <description>EUVD-2026-318572</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-318572</guid>
    </item>
    <item>
      <title>fkie_cve-2026-42597</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42597</link>
      <description>&lt;p&gt;Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the /forms/chromium/convert/url and /forms/chromium/screenshot/url routes accept url=file:///tmp/... from anonymous callers. The default Chromium deny-list intentionally exempts file:///tmp/ so HTML/Markdown routes can load their own request-local assets, and those routes apply a per-request AllowedFilePrefixes guard to scope the read. The URL routes never set AllowedFilePrefixes, so the scope guard silently skips. Alice enumerates /tmp/, walks Gotenberg&amp;#39;s per-request working directories, and reads the raw source files of other in-flight conversions as rendered PDF output. This vulnerability is fixed in 8.32.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the /forms/chromium/convert/url and /forms/chromium/screenshot/url routes accept url=file:///tmp/... from anonymous callers. The default Chromium deny-list intentionally exempts file:///tmp/ so HTML/Markdown routes can load their own request-local assets, and those routes apply a per-request AllowedFilePrefixes guard to scope the read. The URL routes never set AllowedFilePrefixes, so the scope guard silently skips. Alice enumerates /tmp/, walks Gotenberg&amp;#39;s per-request working directories, and reads the raw source files of other in-flight conversions as rendered PDF output. This vulnerability is fixed in 8.32.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-42597</guid>
    </item>
    <item>
      <title>GHSA-g924-cjx7-2rjw — Gotenberg allows Chromium URL conversion routes to read arbitrary files under /tmp via file:// scheme</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g924-cjx7-2rjw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/gotenberg/gotenberg/v8, Go: github.com/gotenberg/gotenberg/v7&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `/forms/chromium/convert/url` and `/forms/chromium/screenshot/url` routes accept `url=file:///tmp/...` from anonymous callers. The default Chromium deny-list intentionally exempts `file:///tmp/` so HTML/Markdown routes can load their own request-local assets, and those routes apply a per-request `AllowedFilePrefixes` guard to scope the read. The URL routes never set `AllowedFilePrefixes`, so the scope guard silently skips. Alice enumerates `/tmp/`, walks Gotenberg&amp;#39;s per-request working directories, and reads the raw source files of other in-flight conversions as rendered PDF output.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The default deny-list regex at `pkg/modules/chromium/chromium.go:449` uses a negative lookahead to exempt `/tmp/`:&lt;/p&gt;
&lt;p&gt;```go
fs.StringSlice(&amp;#34;chromium-deny-list&amp;#34;,
    []string{`^file:(?!//\/tmp/).*`},
    &amp;#34;Set the denied URLs for Chromium using regular expressions - supports multiple values&amp;#34;)
```&lt;/p&gt;
&lt;p&gt;`pkg/gotenberg/outbound.go:185-187` short-circuits IP validation for non-HTTP schemes:&lt;/p&gt;
&lt;p&gt;```go
if !httpLikeScheme(parsed.Scheme) {
    return outboundDecision{}, nil
}
```&lt;/p&gt;
&lt;p&gt;So any `file:///tmp/...` URL passes `FilterOutboundURL` cleanly.&lt;/p&gt;
&lt;p&gt;The HTML route pairs the exemption with a per-request scope guard (`pkg/modules/chromium/routes.go:518`):&lt;/p&gt;
&lt;p&gt;```go
options.AllowedFilePrefixes = []string{ctx.DirPath()}
```&lt;/p&gt;
&lt;p&gt;and the CDP `Fetch.requestPaused` handler enforces the scope (`pkg/modules/chromium/events.go:65-78`):&lt;/p&gt;
&lt;p&gt;```go
if allow &amp;amp;&amp;amp; strings.HasPrefix(e.Request.URL, &amp;#34;file://&amp;#34;) &amp;amp;&amp;amp; len(op…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/gotenberg/gotenberg/v8, Go: github.com/gotenberg/gotenberg/v7&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `/forms/chromium/convert/url` and `/forms/chromium/screenshot/url` routes accept `url=file:///tmp/...` from anonymous callers. The default Chromium deny-list intentionally exempts `file:///tmp/` so HTML/Markdown routes can load their own request-local assets, and those routes apply a per-request `AllowedFilePrefixes` guard to scope the read. The URL routes never set `AllowedFilePrefixes`, so the scope guard silently skips. Alice enumerates `/tmp/`, walks Gotenberg&amp;#39;s per-request working directories, and reads the raw source files of other in-flight conversions as rendered PDF output.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The default deny-list regex at `pkg/modules/chromium/chromium.go:449` uses a negative lookahead to exempt `/tmp/`:&lt;/p&gt;
&lt;p&gt;```go
fs.StringSlice(&amp;#34;chromium-deny-list&amp;#34;,
    []string{`^file:(?!//\/tmp/).*`},
    &amp;#34;Set the denied URLs for Chromium using regular expressions - supports multiple values&amp;#34;)
```&lt;/p&gt;
&lt;p&gt;`pkg/gotenberg/outbound.go:185-187` short-circuits IP validation for non-HTTP schemes:&lt;/p&gt;
&lt;p&gt;```go
if !httpLikeScheme(parsed.Scheme) {
    return outboundDecision{}, nil
}
```&lt;/p&gt;
&lt;p&gt;So any `file:///tmp/...` URL passes `FilterOutboundURL` cleanly.&lt;/p&gt;
&lt;p&gt;The HTML route pairs the exemption with a per-request scope guard (`pkg/modules/chromium/routes.go:518`):&lt;/p&gt;
&lt;p&gt;```go
options.AllowedFilePrefixes = []string{ctx.DirPath()}
```&lt;/p&gt;
&lt;p&gt;and the CDP `Fetch.requestPaused` handler enforces the scope (`pkg/modules/chromium/events.go:65-78`):&lt;/p&gt;
&lt;p&gt;```go
if allow &amp;amp;&amp;amp; strings.HasPrefix(e.Request.URL, &amp;#34;file://&amp;#34;) &amp;amp;&amp;amp; len(op…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g924-cjx7-2rjw</guid>
    </item>
  </channel>
</rss>
