CVE-2026-39087

ntfy before 2.22.0 allows SSRF because of an unanchored regular expression.
Configurations

No configuration.

History

04 May 2026, 06:16

Type Values Removed Values Added
Summary (en) An issue in Ntfy ntfy.sh before v.2.21 allows a remote attacker to execute arbitrary code via the parseActions function (en) ntfy before 2.22.0 allows SSRF because of an unanchored regular expression.
References
  • () https://github.com/binwiederhier/ntfy/releases/tag/v2.22.0 -

23 Apr 2026, 19:17

Type Values Removed Values Added
CWE CWE-94
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

23 Apr 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-23 16:16

Updated : 2026-05-04 06:16


NVD link : CVE-2026-39087

Mitre link : CVE-2026-39087

CVE.ORG link : CVE-2026-39087


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')