PT-2026-20327 · Cern · Indico
Inkz
+2
·
Published
2026-02-17
·
Updated
2026-02-26
·
CVE-2026-25738
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
Indico versions prior to 3.3.10
Description
Indico, an event management system, is susceptible to server-side request forgery (SSRF). The system makes outgoing requests to URLs provided by users. While this functionality is intentional, it could allow access to sensitive targets like localhost or cloud metadata endpoints. The risk is limited to event organizers who can access endpoints where SSRF could be used to view returned data. Users hosted on AWS without authentication for sensitive data are less affected.
Recommendations
Versions prior to 3.3.10 should be upgraded to version 3.3.10.
As a preventative measure, set the
http proxy and https proxy environment variables on both the indico-uwsgi and indico-celery services to force outgoing requests through a limiting proxy.Exploit
Fix
SSRF
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Indico