PT-2026-20327 · Cern · Indico

Inkz

+2

·

Published

2026-02-17

·

Updated

2026-02-26

·

CVE-2026-25738

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Indico versions prior to 3.3.10
Description Indico, an event management system, is susceptible to server-side request forgery (SSRF). The system makes outgoing requests to URLs provided by users. While this functionality is intentional, it could allow access to sensitive targets like localhost or cloud metadata endpoints. The risk is limited to event organizers who can access endpoints where SSRF could be used to view returned data. Users hosted on AWS without authentication for sensitive data are less affected.
Recommendations Versions prior to 3.3.10 should be upgraded to version 3.3.10. As a preventative measure, set the http proxy and https proxy environment variables on both the indico-uwsgi and indico-celery services to force outgoing requests through a limiting proxy.

Exploit

Fix

SSRF

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-25738
GHSA-F47C-3C5W-V7P4

Affected Products

Indico