PT-2026-84037 · Wallos · Wallos

CVE-2026-77348

·

Published

2026-08-31

·

Updated

2026-09-01

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Wallos versions prior to 5.0.0
Description An unauthenticated logo-image search endpoint allows Server-Side Request Forgery (SSRF), a condition where an attacker can induce the server to make requests to an unintended location. The issue exists because the endpoint 'endpoints/payments/search.php' fails to disable cURL proxying, allowing the HTTP PROXY and HTTPS PROXY environment variables to be passed directly into CURLOPT PROXY.
Recommendations Update to version 5.0.0. Restrict access to the 'endpoints/payments/search.php' endpoint as a temporary mitigation measure.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77348
GHSA-F8J2-QM83-R2W4
GHSA-HHJQ-82F8-M6RC

Affected Products

Wallos