Server-Side Request Forgery Vulnerability in Shlink by Shlinkio
CVE-2026-18736

5.3MEDIUM

Key Information:

Vendor

Shlinkio

Status
Vendor
CVE Published:
3 August 2026

What is CVE-2026-18736?

The Shlink application is susceptible to a server-side request forgery vulnerability that can be exploited by authenticated users with an API key. By providing a manipulated long URL during the short URL creation process, especially with the title auto-resolution feature enabled, attackers can trigger the server to make arbitrary HTTP GET requests. This exploitation can allow attackers to redirect requests to internal resources, including sensitive endpoints like cloud metadata services and local addresses, thereby leaking confidential service information through the response data of the short URL generation.

Affected Version(s)

Shlink 2.6.0 <= 5.1.5

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Theodosis Paidakis
.