PT-2026-21371 · Wallos · Wallos

Acorzo1983

·

Publicado

2026-02-21

·

Atualizado

2026-02-21

·

CVE-2026-27479

CVSS v3.1

7.7

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Wallos versions 4.6.0 and below
Description Wallos is a self-hostable personal subscription tracker susceptible to a Server-Side Request Forgery (SSRF) issue in the subscription and payment logo/icon upload functionality. The application validates the IP address of a provided URL, but allows HTTP redirects, enabling an attacker to bypass IP validation and access internal resources, including cloud instance metadata endpoints. The getLogoFromUrl() function uses FILTER FLAG NO PRIV RANGE | FILTER FLAG NO RES RANGE to validate the URL, but the cURL request is configured with CURLOPT FOLLOWLOCATION = true and CURLOPT MAXREDIRS = 3, allowing redirects without re-validation of the destination IP.
Recommendations Update to version 4.6.1 or later.

Exploit

Correção

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-27479
GHSA-FGMF-7G5V-JMJG

Produtos afetados

Wallos