216.73.217.24

CVE-2026-25493

· Published 09/02/2026 20:15 · Modified 09/02/2026 21:55

Labels: CVE-2026-25493 2026-02-09CVE-2026-25493CWE-918[email protected]

Essential information

Published
09/02/2026 20:15
Modified
09/02/2026 21:55
Author
Creator
CVSS
6.9 MEDIUM (v3) 6.9 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the saveAsset GraphQL mutation validates the initial URL hostname and resolved IP against a blocklist, but Guzzle follows HTTP redirects by default. An attacker can bypass all SSRF protections by hosting a redirect that points to cloud metadata endpoints or any internal IP addresses. This issue is patched in versions 4.16.18 and 5.8.22.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
craft / craft cpe:2.3:a:craft:craft:4.0.0-4.16.17:*:*:*:*:*:*:*
craft / craft cpe:2.3:a:craft:craft:5.0.0-5.8.21:*:*:*:*:*:*:*

References