PT-2026-29855 · Postiz · Postiz

·

CVE-2026-34590

·

Published

2026-04-02

·

Updated

2026-04-02

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Postiz versions prior to 2.21.4
Description An issue exists in the creation of webhooks where the POST /webhooks/ endpoint fails to properly validate the url field. While it performs a format check, it lacks a validator to block internal or private network addresses. Consequently, when a post is published, the orchestrator retrieves the stored URL without runtime validation, allowing for blind Server-Side Request Forgery (SSRF)—a technique where an attacker forces a server to make requests to an internal resource—against internal services.
Recommendations Update to version 2.21.4. Avoid using the url parameter in the POST /webhooks/ endpoint to point to internal network addresses until the update is applied.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34590
GHSA-WC9C-7CV8-M225

Affected Products

Postiz