PT-2026-23825 · Wallos · Wallos

Aryma-F4

·

Publicado

2026-03-07

·

Atualizado

2026-03-11

·

CVE-2026-30840

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Wallos versions prior to 4.6.2
Description Wallos is a self-hostable personal subscription tracker. A server-side request forgery condition exists in the notification testers functionality. This allows for potentially malicious requests to be made on the server.
Recommendations Update to version 4.6.2 or later.

Exploit

Correção

SSRF

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-30840
GHSA-MR2C-PRQV-HQM8

Produtos afetados

Wallos