Server-Side Request Forgery Vulnerability in Shlink by Shlinkio
CVE-2026-18736
5.3MEDIUM
What is CVE-2026-18736?
The Shlink application is susceptible to a server-side request forgery vulnerability that can be exploited by authenticated users with an API key. By providing a manipulated long URL during the short URL creation process, especially with the title auto-resolution feature enabled, attackers can trigger the server to make arbitrary HTTP GET requests. This exploitation can allow attackers to redirect requests to internal resources, including sensitive endpoints like cloud metadata services and local addresses, thereby leaking confidential service information through the response data of the short URL generation.
Affected Version(s)
Shlink 2.6.0 <= 5.1.5
