SB2026082520 - Server-Side Request Forgery (SSRF) in Contao



SB2026082520 - Server-Side Request Forgery (SSRF) in Contao

Published: August 25, 2026

Security Bulletin ID SB2026082520
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Server-Side Request Forgery (SSRF) (CVE-ID: CVE-2026-57232)

CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)

CVSSv4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to access internal network services and disclose sensitive information.

The vulnerability exists due to server-side request forgery (SSRF) in the Feed Reader front-end module when processing configured RSS feed URLs. A remote user can configure an arbitrary URL to cause the server to fetch internal resources and disclose sensitive information.

The issue can expose loopback services, internal network endpoints, and cloud metadata endpoints.


Remediation

Install update from vendor's website.