PSA-2026-04-SRGACVE-2024-34351GCVE-125-2026-04-SRGAApril 19, 2026High-Severity SSRF in Postiz App
High-Severity SSRF in Postiz App
Affected (1)
- gitroomhqpostiz-app
- ≥ 0Fixed in 2.21.1Affected
All other versions: Unaffected
Mitigations
Solutions
- Upgrade to v2.21.1 or later.
Exploits
- Access to the internal network / services where Postiz is hosted.
Overview
Impact
A successful SSRF attack allows an attacker to:
- Bypass firewalls to scan and interact with internal network services/ports.
- Access sensitive cloud metadata services (e.g., AWS IMDS 169.254.169.254) to potentially leak instance credentials.
- Pivot into the internal network environment where Postiz is hosted.
Workarounds
There are no workarounds known to this, please upgrade to Postiz version v2.21.1.
References
https://nvd.nist.gov/vuln/detail/CVE-2024-34351 http://cwe.mitre.org/data/definitions/918.html https://github.com/vercel/next.js/security/advisories/GHSA-fr5h-rqp8-mj6g
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- None
- Availability
- None
Weaknesses (1)
References (3)
- GHSA (Next.js) (Vendor advisory)
- GHSA (Postiz) (Vendor advisory)
- CVE-2024-34351 (Technical description)
Credits (2)
- Enno GelhausCoordinator · @egelhaus
- Nevo DavidRemediation developer · @nevo-david
Context
Impacts
Impacts could include: - Access sensitive cloud metadata services (e.g., AWS IMDS 169.254.169.254) to potentially leak instance credentials. - Access to sensitive internal services on the internal network. - Access to services used by Postiz. (Like Redis, PostgreSQL, Temporal etc.)
Timeline
- 03/24/2026 14:58
Postiz received the initial report for the vulnerability.
- 03/25/2026 10:15
Postiz developed the fix, verified it, created the release and published the advisory.