PT-2026-83455 · Memos · Memos

·

CVE-2026-82476

·

Published

2026-08-29

·

Updated

2026-08-30

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Memos versions prior to 0.30.1
Description The link-metadata fetcher fails to include the 100.64.0.0/10 carrier-grade NAT (CGNAT) address range in its SSRF protection. This allows unauthenticated attackers to bypass IP validation and force the server to make requests to internal hosts within that range, including cloud metadata services, enabling the retrieval of page titles and descriptions.
Recommendations Update Memos to version 0.30.1 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82476

Affected Products

Memos