CVE-2026-77348
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, the fix for CVE-2026-33407 (GHSA-hhjq-82f8-m6
CVSS
8.2
Alto
EPSS
0.2%
p16
KEV
—
Exploit Today
5
0-100
Publicado: 31 ago 2026 · Última mod.: 3 sept 2026 · CWE-441 · CWE-918 · CWE-1188
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, the fix for CVE-2026-33407 (GHSA-hhjq-82f8-m6rc, "SSRF via HTTP Proxy Environment Variable") hardened endpoints/logos/search.php by disabling cURL proxying (CURLOPT_PROXY = '' + CURLOPT_NOPROXY = '*'). However, Wallos ships a second, near-identical, unauthenticated logo-image search endpoint — endpoints/payments/search.php — that was not given the same hardening. It still passes the HTTP_PROXY/HTTPS_PROXY environment variable straight into CURLOPT_PROXY. This issue has been patched in version 5.0.0.
- github.comhttps://github.com/ellite/Wallos/commit/11eaf402e841a628c68a805694227ce66c45f6f3
- github.comhttps://github.com/ellite/Wallos/releases/tag/v5.0.0
- github.comhttps://github.com/ellite/Wallos/security/advisories/GHSA-f8j2-qm83-r2w4
- github.comhttps://github.com/ellite/Wallos/security/advisories/GHSA-hhjq-82f8-m6rc
- github.comhttps://github.com/ellite/Wallos/security/advisories/GHSA-f8j2-qm83-r2w4
- github.comhttps://github.com/ellite/Wallos/security/advisories/GHSA-hhjq-82f8-m6rc