PT-2026-52545 · Samuelclay · Newsblur

George Chen

·

Publicado

2026-06-25

·

Atualizado

2026-06-25

·

CVE-2026-56771

CVSS v3.1

8.5

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N
NewsBlur before version 14.5.0 contains a server-side request forgery vulnerability in the add url endpoint that allows authenticated users to make arbitrary server requests to internal networks by failing to filter private IP addresses. Attackers can exploit this to access localhost services and cloud metadata endpoints, enabling internal network scanning and sensitive data exfiltration.

Correção

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-56771

Produtos afetados

Newsblur