CVE-2026-56771

NewsBlur before version 14.5.0 contains a server-side request forgery vulnerability in the add_url endpoint that allows authenticated users to make arbitrary server requests to internal networks by failing to filter private IP addresses. Attackers can exploit this to access localhost services and cloud metadata endpoints, enabling internal network scanning and sensitive data exfiltration.
Configurations

No configuration.

History

25 Jun 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-25 19:16

Updated : 2026-06-26 04:17


NVD link : CVE-2026-56771

Mitre link : CVE-2026-56771

CVE.ORG link : CVE-2026-56771


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)