← Back to CVE search

CVE-2026-45660

Statamic

Description

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.22 and 6.18.1, the Glide image proxy-s URL validation could be bypassed using an IP representation that wasn-t normalized before the public-IP check. An unauthenticated user could cause the server to make HTTP requests to internal addresses — including loopback, private network, and cloud metadata endpoints. This affects sites that pass user-supplied URLs to Glide. Sites running PHP 8.3 or newer are not affected. This vulnerability is fixed in 5.73.22 and 6.18.1.

CVSS 5.4EPSS 0.151%Risk 0.55
View source
Published
2026-05-29 18:17:11
Affected versions
<5.73.22, <6.18.1
Type
Installed app
Last modified
2026-07-22 06:10:00
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N