PT-2026-34563 · Squidex · Squidex

Published

2026-04-22

·

Updated

2026-04-23

·

CVE-2026-41170

CVSS v4.0

8.5

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Squidex versions prior to 7.23.0
Description The RestoreController.PostRestoreJob endpoint allows an administrator to provide an arbitrary URL for downloading backup archives. This URL is processed by the HttpClient without Server-Side Request Forgery (SSRF) protection, which is a flaw where a server is tricked into making requests to an unintended location. An authenticated administrator can exploit this to probe internal network services, access cloud metadata endpoints, or conduct internal reconnaissance.
Recommendations Update to version 7.23.0.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41170

Affected Products

Squidex