VDB
GO-2026-4905
GO-2026-4905
PUBLISHED
Gotenberg has Chromium deny-list bypass via case-insensitive URL scheme (bypass of GHSA-rh2x-ccvw-q7r3) in github.com/gotenberg/gotenberg
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | gotenberg/gotenberg/v7 | 0, 0 |
| github.com | gotenberg/gotenberg/v8 | 0, 0 |
Timeline
- Apr 2, 2026 CVE Published
- Apr 2, 2026 CVE Updated
References
- https://github.com/gotenberg/gotenberg/security/advisories/GHSA-jjwv-57xh-xr6r advisory
- https://github.com/gotenberg/gotenberg/commit/06b2b2e10c52b58135edbfe82e94d599eb0c5a11 url
- https://github.com/gotenberg/gotenberg/commit/8625a4e899eb75e6fcf46d28394334c7fd79fff5 url
- https://github.com/gotenberg/gotenberg/releases/tag/v8.29.0 url
- https://github.com/gotenberg/gotenberg/security/advisories/GHSA-rh2x-ccvw-q7r3 url