Description


Mealie 3.26.0 through 3.28.0 contains a server-side request forgery vulnerability in the OpenID Connect avatar fetch that ignores ports when allowlisting the identity provider hostname. Authenticated OIDC users who control their picture URL can make the server send GET requests to arbitrary ports on the provider's internal address on each login.

Related CPE's


Could not find any relations

Weaknesses



CWE-918

CVSS impact metrics


CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N

3.5 · Low

Information


Source identifier

[email protected]

Vulnerability status

Deferred

Published

2026-10-10T19:16:57.770Z

1 hour ago

Last modified

2026-10-10T19:16:57.880Z

1 hour ago