PSA-2026-04-ZR1MGHSA-89v5-38xr-9m4jGCVE-125-2026-04-ZR1MApril 19, 20267.1 High
Multiple SSRF Vectors - Webhooks, RSS Feed, URL Loader (CWE-918)
Multiple SSRF Vectors - Webhooks, RSS Feed, URL Loader (CWE-918)
Affected (1)
- gitroomhqpostiz-app
- ≥ 0Fixed in 2.21.2Affected
All other versions: Unaffected
Mitigations
Solutions
- Upgrading to version v2.21.2 or later.
Overview
Postiz has multiple SSRF vulnerabilities where user-provided URLs are fetched server-side without any IP validation or SSRF protection.
Severity
CVSS v3
7.1 High
7.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- Low
- User Interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- Low
- Availability
- None
Weaknesses (1)
References (2)
Credits (3)
- Kevin ChenReporter · @cwanglab
- Enno GelhausCoordinator · @egelhaus
- Nevo DavidRemediation developer · @nevo-david
Context
Impacts
Impacts could include: - Cloud metadata theft: AWS/GCP/Azure credentials - Internal network scanning: Full access to private IP ranges - Multiple entry points: Webhooks, RSS feeds, URL loader all vulnerable
Timeline
- 03/04/2026 20:33
Report has been disclosed privately to Postiz.
- 03/25/2026 10:24
Postiz acknowledged the report.
- 03/25/2026 10:48
Postiz created a fix, created a release (v2.21.2) and published the advisory.