Time-of-check Time-of-use (TOCTOU) Race Condition in Zammad - #VU153218
Published: October 3, 2026
Vulnerability details
The vulnerability allows a remote attacker to access internal-only network resources.
The vulnerability exists due to a time-of-check time-of-use race condition in the hostname safety check when validating and fetching an attacker-supplied URL. A remote attacker can manipulate DNS responses for a controlled domain to direct requests to internal addresses.
An administrator must configure the attacker-supplied URL, and exploitation depends on a DNS-timing race.