← Zurück zur CVE-Suche

CVE-2026-45660

Statamic

Beschreibung

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.22 and 6.18.1, the Glide image proxy-s URL validation could be bypassed using an IP representation that wasn-t normalized before the public-IP check. An unauthenticated user could cause the server to make HTTP requests to internal addresses — including loopback, private network, and cloud metadata endpoints. This affects sites that pass user-supplied URLs to Glide. Sites running PHP 8.3 or newer are not affected. This vulnerability is fixed in 5.73.22 and 6.18.1.

CVSS 5.4EPSS 0.151%Risiko 0.55
Quelle öffnen
Veröffentlicht
2026-05-29 18:17:11
Betroffene Versionen
<5.73.22, <6.18.1
Typ
Installed app
Zuletzt geändert
2026-07-22 06:10:00
Vektor
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N