PT-2026-67503 · Shlink · Shlink
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Shlink (affected versions not specified)
Description
Authenticated API key holders can trigger server-side request forgery (SSRF), a flaw where the server is coerced into making unauthorized requests. By providing a crafted long URL during the short URL creation process while title auto-resolution is enabled, an attacker can force the server to issue arbitrary HTTP GET requests. This can be achieved by using public hosts that redirect to internal targets, such as loopback addresses, link-local ranges, or cloud metadata endpoints like 169.254.169.254. Internal service information can then be exfiltrated through the HTML title element returned in the response.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Shlink