PT-2026-52545 · Newsblur · Newsblur

·

CVE-2026-56771

·

Published

2026-06-25

·

Updated

2026-06-26

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions NewsBlur versions prior to 14.5.0
Description Authenticated users can perform server-side request forgery (SSRF) via the 'add url' endpoint. This occurs because the application fails to filter private IP addresses, allowing arbitrary server requests to internal networks. This can be used to access localhost services and cloud metadata endpoints, facilitating internal network scanning and the exfiltration of sensitive data.
Recommendations Update to version 14.5.0 or later. As a temporary mitigation, restrict access to the 'add url' endpoint.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56771

Affected Products

Newsblur