CVE-2026-27797

Homarr is an open-source dashboard. Prior to version 1.54.0, an unauthenticated Server-Side Request Forgery (SSRF) vulnerability allows a remote attacker to force the Homarr server to perform arbitrary outbound HTTP requests. This can be used as an internal network access primitive (e.g., reaching loopback/private ranges) from the Homarr host/container network context. This issue has been patched in version 1.54.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:homarr:homarr:*:*:*:*:*:*:*:*

History

10 Mar 2026, 16:24

Type Values Removed Values Added
Summary
  • (es) Homarr es un panel de control de código abierto. Antes de la versión 1.54.0, una vulnerabilidad de falsificación de petición del lado del servidor (SSRF) no autenticada permite a un atacante remoto forzar al servidor Homarr a realizar peticiones HTTP salientes arbitrarias. Esto puede ser utilizado como una primitiva de acceso a la red interna (por ejemplo, alcanzando rangos de loopback/privados) desde el contexto de red del host/contenedor de Homarr. Este problema ha sido parcheado en la versión 1.54.0.
References () https://github.com/homarr-labs/homarr/commit/fce970c70653f200ff1c73081139a77f0379bd91 - () https://github.com/homarr-labs/homarr/commit/fce970c70653f200ff1c73081139a77f0379bd91 - Patch
References () https://github.com/homarr-labs/homarr/releases/tag/v1.54.0 - () https://github.com/homarr-labs/homarr/releases/tag/v1.54.0 - Release Notes
References () https://github.com/homarr-labs/homarr/security/advisories/GHSA-vwqf-2f4m-2cq2 - () https://github.com/homarr-labs/homarr/security/advisories/GHSA-vwqf-2f4m-2cq2 - Exploit, Mitigation, Vendor Advisory
First Time Homarr
Homarr homarr
CPE cpe:2.3:a:homarr:homarr:*:*:*:*:*:*:*:*

07 Mar 2026, 06:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-07 06:16

Updated : 2026-03-10 16:24


NVD link : CVE-2026-27797

Mitre link : CVE-2026-27797

CVE.ORG link : CVE-2026-27797


JSON object : View

Products Affected

homarr

  • homarr
CWE
CWE-918

Server-Side Request Forgery (SSRF)