PT-2026-38445 · Ellite · Wallos

Published

2026-05-07

·

Updated

2026-05-07

·

CVE-2026-41688

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the incomplete SSRF fix in Wallos validates webhook URLs via gethostbyname() but passes the original hostname to cURL without CURLOPT RESOLVE pinning on 10 of 11 outbound HTTP endpoints, leaving a DNS rebinding TOCTOU window. At time of publication, there are no publicly available patches.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-41688

Affected Products

Wallos