SB2026082520 - Server-Side Request Forgery (SSRF) in Contao
Published: August 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Server-Side Request Forgery (SSRF) (CVE-ID: CVE-2026-57232)
CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)
CVSSv4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to access internal network services and disclose sensitive information.
The vulnerability exists due to server-side request forgery (SSRF) in the Feed Reader front-end module when processing configured RSS feed URLs. A remote user can configure an arbitrary URL to cause the server to fetch internal resources and disclose sensitive information.
The issue can expose loopback services, internal network endpoints, and cloud metadata endpoints.
Remediation
Install update from vendor's website.