PT-2026-68048 · Mealie · Mealie

·

CVE-2026-71210

·

Published

2026-08-05

·

Updated

2026-08-10

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mealie (affected versions not specified)
Description The AsyncSafeTransport SSRF guard in mealie/pkgs/safehttp/transport.py fails to pin the validated IP address to the actual connection. The system resolves the target hostname to check it against private-range rules but then performs the outbound HTTP request using the original hostname, causing the transport to re-resolve the address. This allows a DNS-rebinding attack, where an attacker provides a public IP during validation and a private or metadata IP during the actual connection. Authenticated users can exploit this via the endpoints '/api/recipes/create/url', '/api/recipes/test-scrape-url', and '/api/recipes/{slug}/image' to read internal HTTP services and cloud-metadata endpoints.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71210

Affected Products

Mealie