PT-2026-23830 · Homarr · Homarr

Ormzro

·

Publicado

2026-03-07

·

Atualizado

2026-03-10

·

CVE-2026-27797

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Homarr versions prior to 1.54.0
Description An unauthenticated Server-Side Request Forgery (SSRF) exists in Homarr, allowing a remote attacker to force the server to perform arbitrary outbound HTTP requests. This can be used to access internal networks from the Homarr host or container network. The vulnerability is present in versions before 1.54.0. SSRF is a web security flaw that allows an attacker to cause the server to make HTTP requests to an arbitrary domain of the attacker’s choosing.
Recommendations Update to version 1.54.0 or later.

Exploit

Correção

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-27797
GHSA-VWQF-2F4M-2CQ2

Produtos afetados

Homarr