PT-2026-58809 · Simple Machines+1 · Smf

·

CVE-2026-61520

·

Published

2026-07-14

·

Updated

2026-07-14

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Simple Machines Forum versions 2.1 prior to commit 4bf35cf Simple Machines Forum versions 3.0 prior to commit b4d23df
Description The image proxy allows authenticated attackers to trigger internal HTTP requests by embedding attacker-controlled URLs in BBCode image tags. The proxy fetches these URLs without validating resolved destination IPs against loopback, link-local, or private address ranges. Attackers can use the automatic HMAC (Hash-based Message Authentication Code) signature generation to create valid signed proxy requests targeting internal services, including container network services, internal web applications, and cloud instance metadata endpoints.
Recommendations Update Simple Machines Forum version 2.1 to commit 4bf35cf or later. Update Simple Machines Forum version 3.0 to commit b4d23df or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61520

Affected Products

Smf