Skip to content
PSA-2026-04-ZR1MGHSA-89v5-38xr-9m4jGCVE-125-2026-04-ZR1MApril 19, 2026
7.1 High

Multiple SSRF Vectors - Webhooks, RSS Feed, URL Loader (CWE-918)

Multiple SSRF Vectors - Webhooks, RSS Feed, URL Loader (CWE-918)

Affected (1)

  • gitroomhqpostiz-app
    • ≥ 0Fixed in 2.21.2Affected

    All other versions: Unaffected

Mitigations

Solutions

  • Upgrading to version v2.21.2 or later.

Overview

Postiz has multiple SSRF vulnerabilities where user-provided URLs are fetched server-side without any IP validation or SSRF protection.

Severity

CVSS v3
7.1 High
7.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None

Weaknesses (1)

References (2)

Credits (3)

  • Kevin Chen
    Reporter · @cwanglab
  • Enno Gelhaus
    Coordinator · @egelhaus
  • Nevo David
    Remediation developer · @nevo-david

Context

Impacts

  • Impacts could include: - Cloud metadata theft: AWS/GCP/Azure credentials - Internal network scanning: Full access to private IP ranges - Multiple entry points: Webhooks, RSS feeds, URL loader all vulnerable

Timeline

  1. 03/04/2026 20:33

    Report has been disclosed privately to Postiz.

  2. 03/25/2026 10:24

    Postiz acknowledged the report.

  3. 03/25/2026 10:48

    Postiz created a fix, created a release (v2.21.2) and published the advisory.

© 2026 Gelhaus Solutions