PT-2026-67503 · Shlink · Shlink

·

CVE-2026-18736

·

Published

2026-08-03

·

Updated

2026-08-04

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Shlink (affected versions not specified)
Description Authenticated API key holders can trigger server-side request forgery (SSRF), a flaw where the server is coerced into making unauthorized requests. By providing a crafted long URL during the short URL creation process while title auto-resolution is enabled, an attacker can force the server to issue arbitrary HTTP GET requests. This can be achieved by using public hosts that redirect to internal targets, such as loopback addresses, link-local ranges, or cloud metadata endpoints like 169.254.169.254. Internal service information can then be exfiltrated through the HTML title element returned in the response.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18736

Affected Products

Shlink