PT-2026-83455 · Memos · Memos
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Memos versions prior to 0.30.1
Description
The link-metadata fetcher fails to include the 100.64.0.0/10 carrier-grade NAT (CGNAT) address range in its SSRF protection. This allows unauthenticated attackers to bypass IP validation and force the server to make requests to internal hosts within that range, including cloud metadata services, enabling the retrieval of page titles and descriptions.
Recommendations
Update Memos to version 0.30.1 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Memos