CVE-2026-33953
EUVD-2026-1686827.03.2026, 22:16
LinkAce is a self-hosted archive to collect website links. Versions prior to 2.5.3 block direct requests to private IP literals, but still performs server-side requests to internal-only resources when those resources are referenced through an internal hostname. This allows an authenticated user to trigger server-side requests to internal services reachable by the LinkAce server but not directly reachable by an external user. Version 2.5.3 patches the issue.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| linkace | linkace | 𝑥 < 2.5.3 |
𝑥
= Vulnerable software versions