Two high-severity vulnerabilities were disclosed in Gotenberg, the document-conversion API, affecting separate parts of the product’s request-handling logic. CVE-2026-27018 allows a deny-list bypass in Chromium-based processing because protections added for CVE-2024-21527 can be evaded with mixed-case or uppercase URL schemes, creating exposure associated with CWE-22 and CWE-918. The flaw is remotely reachable with low attack complexity and requires no privileges or user interaction, according to the published CVSS v4 metadata.
A second issue, CVE-2026-35458, affects Gotenberg 8.29.1 and earlier and can be exploited for regular expression denial of service through the extraHttpHeaders scope feature. User-supplied scope patterns are compiled with dlclark/regexp2 without an adequate timeout, allowing authorized users of the affected feature to hang workers indefinitely and degrade service availability. The SSRF-related bypass was patched in Gotenberg 8.29.0, while the ReDoS issue highlights an additional availability risk for deployments that expose header-scoping functionality.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
A new vulnerability, CVE-2026-35458, was recorded for Gotenberg affecting version 8.29.1 and earlier. The flaw stems from compiling user-supplied scope patterns with dlclark/regexp2 without a proper timeout, allowing workers to be hung indefinitely and causing availability impact.
The CVE-2026-27018 advisory for Gotenberg was received by security-advisories@github.com. The issue was classified under CWE-22 and CWE-918 and described as network exploitable with low attack complexity.
Gotenberg fixed a vulnerability later assigned CVE-2026-27018 in version 8.29.0. The flaw allowed bypass of the prior CVE-2024-21527 fix by using mixed-case or uppercase URL schemes, enabling deny-list evasion.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.