PT-2026-27470 · Wallos · Wallos

B-Hermes

·

Publicado

2026-03-24

·

Atualizado

2026-03-24

·

CVE-2026-33401

CVSS v4.0

7.1

Alta

VetorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Wallos versions prior to 4.7.0
Description Wallos is a self-hostable, open-source personal subscription tracker. An authenticated user can potentially access internal network services, cloud metadata endpoints like AWS IMDSv1, GCP, and Azure IMDS, or services bound to localhost. This is possible by providing a manipulated URL to the AI Ollama host parameter, the AI recommendations endpoint, or the notification cron job. The patch introduced in commit e8a513591 added Server-Side Request Forgery (SSRF) protection to notification test endpoints but did not cover these additional attack surfaces.
Recommendations Update to version 4.7.0 or later.

Exploit

Correção

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-33401
GHSA-R82V-P8CG-RGX3

Produtos afetados

Wallos