CVE-2025-44594
09.09.2025, 20:15
halo v2.20.17 and before is vulnerable to server-side request forgery (SSRF) in /apis/uc.api.storage.halo.run/v1alpha1/attachments/-/upload-from-url.
| Vendor | Product | Version |
|---|---|---|
| halo | halo | 𝑥 ≤ 2.20.17 |
𝑥
= Vulnerable software versions