CVE-2026-64799
Content-controlled image URLs could request private or reserved network services, follow unsafe redirects and save responses without validat
CVSS
—
No CVSS
EPSS
0.2%
p10
KEV
—
Exploit Today
3
0-100
Published: Jul 23, 2026 · Last modified: Jul 23, 2026 · CWE-918
Not enough EPSS history yet.
Content-controlled image URLs could request private or reserved network services, follow unsafe redirects and save responses without validating that they were images. This could result in SSRF, internal-data access or writing attacker-controlled files into a web-accessible folder.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-655167.2 HIG—
——0Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.6hCVE-2026-654964.4 MED—
——0Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions.6hCVE-2026-654674.9 MED—
——0Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions.6hCVE-2026-654664.9 MED—
——0Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 versions.6hCVE-2026-246394.4 MED—
——0Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions.6hCVE-2026-64873—7.8%
——2Custom query URLs could access internal or reserved network services.8h