immich is a high performance self-hosted photo and video management solution. Prior to version 2.6.0, the Immich application is vulnerable to credential disclosure when a user authenticates to a shared album. During the authentication process, the application transmits the album password within the URL query parameters in a GET request to /api/shared-links/me. This exposes the password in browser history, proxy and server logs, and referrer headers, allowing unintended disclosure of authentication credentials. The impact of this vulnerability is the potential compromise of shared album access and unauthorized exposure of sensitive user data. This issue has been patched in version 2.6.0.
References
| Link | Resource |
|---|---|
| https://github.com/immich-app/immich/pull/26868 | Issue Tracking Patch |
| https://github.com/immich-app/immich/pull/26886 | Issue Tracking Patch |
| https://github.com/immich-app/immich/releases/tag/v2.6.0 | Product Release Notes |
| https://github.com/immich-app/immich/security/advisories/GHSA-78x4-6x83-jx75 | Exploit Mitigation Vendor Advisory |
Configurations
History
15 Apr 2026, 18:38
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| CPE | cpe:2.3:a:futo:immich:*:*:*:*:*:docker:*:* | |
| First Time |
Futo immich
Futo |
|
| References | () https://github.com/immich-app/immich/pull/26868 - Issue Tracking, Patch | |
| References | () https://github.com/immich-app/immich/pull/26886 - Issue Tracking, Patch | |
| References | () https://github.com/immich-app/immich/releases/tag/v2.6.0 - Product, Release Notes | |
| References | () https://github.com/immich-app/immich/security/advisories/GHSA-78x4-6x83-jx75 - Exploit, Mitigation, Vendor Advisory |
03 Apr 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-03 16:16
Updated : 2026-04-15 18:38
NVD link : CVE-2026-25118
Mitre link : CVE-2026-25118
CVE.ORG link : CVE-2026-25118
JSON object : View
Products Affected
futo
- immich
CWE
CWE-598
Use of GET Request Method With Sensitive Query Strings
