Server-Side Request Forgery in Mealie by Mealie Recipes
CVE-2026-108594
2.3LOW
What is CVE-2026-108594?
Mealie versions 3.26.0 to 3.28.0 contain a server-side request forgery vulnerability that allows authenticated OpenID Connect (OIDC) users to exploit avatar picture URLs. Specifically, this vulnerability arises because the system fails to restrict access to specified ports when allowlisting identity provider hostnames. As a result, an attacker could manipulate the server into sending unauthorized GET requests to those ports on the internal address of the OIDC provider during each login. This could potentially expose sensitive internal services or data.
Affected Version(s)
mealie 3.26.0 <= 3.28.0
References
CVSS V4
Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
HaiND from the Post and Telecommunication Institute of Technology
