PULSE
EN VIVO53señales / 24h
FEED
ransomnova reclama a Digital Edge · SG · Technologyransomincransom reclama a autismuslink.ch · CH · Healthcareransomplay reclama a Record Go Alquiler · ES · Hospitalityransomplay reclama a Restaurant Depot · US · Retail & E-Commerceransomplay reclama a The DeBruler · US · Not Foundransomincransom reclama a cabincreekhealth.com · US · Healthcareransomcmdorganization reclama a T Simon Jewelers · US · Retail & E-Commerceransomkillsec reclama a cashcowboy · US · Financial Servicesransomkillsec reclama a Bulwark Exterminating · US · Otherransomkillsec reclama a origins ivf · IN · Healthcareransomqilin reclama a Machinerie P&W · CA · Manufacturingransomqilin reclama a ABM Enviro · CA · Professional Servicesransomkrybit reclama a nilepet.com · EG · Retail & E-Commerceransomthegentlemen reclama a European Design · CA · Otherransomnova reclama a Digital Edge · SG · Technologyransomincransom reclama a autismuslink.ch · CH · Healthcareransomplay reclama a Record Go Alquiler · ES · Hospitalityransomplay reclama a Restaurant Depot · US · Retail & E-Commerceransomplay reclama a The DeBruler · US · Not Foundransomincransom reclama a cabincreekhealth.com · US · Healthcareransomcmdorganization reclama a T Simon Jewelers · US · Retail & E-Commerceransomkillsec reclama a cashcowboy · US · Financial Servicesransomkillsec reclama a Bulwark Exterminating · US · Otherransomkillsec reclama a origins ivf · IN · Healthcareransomqilin reclama a Machinerie P&W · CA · Manufacturingransomqilin reclama a ABM Enviro · CA · Professional Servicesransomkrybit reclama a nilepet.com · EG · Retail & E-Commerceransomthegentlemen reclama a European Design · CA · Other
← Todos los CVEs
CVE Watch23 jul 2026

CVE-2026-48013

Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the `/api/_action/media/external-link` endpoint allows authenticated

CVSS

4.1

Medio

EPSS

KEV

Exploit Today

0-100

Publicado: 23 jul 2026 · Última mod.: 23 jul 2026 · CWE-918

EPSS · 30d

Sin historial EPSS suficiente todavía.

Descripción técnica

Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the `/api/_action/media/external-link` endpoint allows authenticated admin users to make server-side HTTP HEAD requests to arbitrary internal IP addresses. While the parallel `uploadFromURL` flow validates target IPs against private/reserved ranges via `FileUrlValidator`, the `linkURL` flow only performs a URL format check (regex for `http://` or `https://` prefix), allowing SSRF to internal network services and cloud metadata endpoints. This issue is fixed in versions 6.6.10.18 and 6.7.10.1.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-633137.7 ALT
9Router before 0.4.72 contains a server-side request forgery (SSRF) vulnerability in the /v1/web/fetch endpoint. The endpoint accepts a user-controlled url parameter and passes it to a configured external scraping provider (Firecrawl, Jina Reader, Tavily, or Exa) to fetch content. The URL is only validated as syntactically valid via new URL() with no blocklist for private IP ranges, cloud metadata endpoints (e.g., 169.254.169.254), link-local addresses, or internal hostnames. An authenticated or locally-connected user can cause the server to fetch arbitrary internal URLs and have the response content returned, enabling read-access SSRF that can expose cloud metadata credentials, reach internal services, and bypass authentication on localhost endpoints.8h
CVE-2026-655167.2 ALT
0Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.14h
CVE-2026-654964.4 MED
0Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions.15h
CVE-2026-654674.9 MED
0Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions.14h
CVE-2026-654664.9 MED
0Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 versions.15h
CVE-2026-246394.4 MED
0Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions.15h
CVE-2026-48013 — Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the `/ap · Pulse | Pulse