CVE-2026-61520

Simple Machines Forum 2.1 prior to commit 4bf35cf and 3.0 prior to commit b4d23df contains a server-side request forgery vulnerability in the image proxy that allows authenticated attackers to trigger internal HTTP requests by embedding attacker-controlled URLs in BBCode image tags, which the proxy fetches without validating resolved destination IPs against private address ranges, loopback, or link-local addresses. Attackers can leverage SMF's automatic HMAC signature generation for any embedded image URL to obtain valid signed proxy requests targeting internal services such as cloud instance metadata endpoints, internal web applications, and container network services.
Configurations

No configuration.

History

14 Jul 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-14 21:17

Updated : 2026-07-15 21:02


NVD link : CVE-2026-61520

Mitre link : CVE-2026-61520

CVE.ORG link : CVE-2026-61520


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)