CVE-2026-72597
EUVD-2026-5603611.08.2026, 12:17
A server-side request forgery vulnerability in Friendica through the 2026.08-dev branch allows authenticated users with a free self-registered account to probe internal network services via the link-preview endpoint. The endpoint fetches any user-supplied URL without applying an internal IP deny list. An attacker can use this to scan the internal network or access cloud metadata services.
Awaiting analysis
This vulnerability is currently awaiting analysis.
References