CVE-2026-71210
EUVD-2026-5320705.08.2026, 08:16
Mealie's AsyncSafeTransport SSRF guard (mealie/pkgs/safehttp/transport.py) resolves a target hostname once, checks the resolved IP against private-range rules, but then issues the actual outbound HTTP request using the original hostname, which the underlying async transport re-resolves independently.
Awaiting analysis
This vulnerability is currently awaiting analysis.
References