#VU125919 Server-Side Request Forgery (SSRF) in EspoCRM - CVE-2026-33534
Published: April 14, 2026
EspoCRM
EspoCRM
Description
The vulnerability allows a remote user to make requests to internal resources and disclose sensitive information.
The vulnerability exists due to server-side request forgery (SSRF) in the /api/v1/Attachment/fromImageUrl endpoint when processing a user-supplied image URL containing an alternative IPv4 representation. A remote user can send a specially crafted request using octal IPv4 notation to make requests to internal resources and disclose sensitive information.
In the confirmed flow, the fetched response is stored as an attachment.