CVE-2026-28423

Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, when Glide image manipulation is used in insecure mode (which is not the default), the image proxy can be abused by an unauthenticated user to make the server send HTTP requests to arbitrary URLs—either via the URL directly or via the watermark feature. That can allow access to internal services, cloud metadata endpoints, and other hosts reachable from the server. This has been fixed in 5.73.11 and 6.4.0.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:statamic:statamic:*:*:*:*:*:*:*:*
cpe:2.3:a:statamic:statamic:*:*:*:*:*:*:*:*

History

05 Mar 2026, 14:47

Type Values Removed Values Added
CPE cpe:2.3:a:statamic:statamic:*:*:*:*:*:*:*:*
First Time Statamic statamic
Statamic
References () https://github.com/statamic/cms/releases/tag/v5.73.11 - () https://github.com/statamic/cms/releases/tag/v5.73.11 - Release Notes
References () https://github.com/statamic/cms/releases/tag/v6.4.0 - () https://github.com/statamic/cms/releases/tag/v6.4.0 - Release Notes
References () https://github.com/statamic/cms/security/advisories/GHSA-cwpp-325q-2cvp - () https://github.com/statamic/cms/security/advisories/GHSA-cwpp-325q-2cvp - Patch, Vendor Advisory
Summary
  • (es) Statmatic es un sistema de gestión de contenido (CMS) impulsado por Laravel y Git. Antes de las versiones 5.73.11 y 6.4.0, cuando la manipulación de imágenes de Glide se utiliza en modo inseguro (lo cual no es el predeterminado), el proxy de imágenes puede ser explotado por un usuario no autenticado para hacer que el servidor envíe solicitudes HTTP a URLs arbitrarias, ya sea directamente a través de la URL o mediante la función de marca de agua. Eso puede permitir el acceso a servicios internos, endpoints de metadatos en la nube y otros hosts accesibles desde el servidor. Esto ha sido corregido en las versiones 5.73.11 y 6.4.0.

27 Feb 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-27 23:16

Updated : 2026-03-05 14:47


NVD link : CVE-2026-28423

Mitre link : CVE-2026-28423

CVE.ORG link : CVE-2026-28423


JSON object : View

Products Affected

statamic

  • statamic
CWE
CWE-918

Server-Side Request Forgery (SSRF)