Server-Side Request Forgery (SSRF) in Shopware - #VU145373
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information and modify data via server-side request forgery.
The vulnerability exists due to server-side request forgery in the Shopware App System request handling for app-provided webhook, payment, tax, checkout, and context gateway URLs when processing app-provided URLs. A remote privileged user can use DNS rebinding in a crafted app-provided URL to disclose sensitive information and modify data via server-side request forgery.
User interaction is required to install or use a malicious or compromised app.