Server-Side Request Forgery (SSRF) in Shopware - #VU145371
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information from internal network services.
The vulnerability exists due to server-side request forgery (SSRF) in the media URL import feature when importing media from an external URL. A remote user can supply a URL that bypasses IP validation through DNS rebinding to disclose sensitive information from internal network services.
The issue may expose cloud-instance metadata depending on the hosting environment.