Blind SQL Injection in Shlink API by Shlink.io
CVE-2026-18737
7.1HIGH
What is CVE-2026-18737?
Shlink is subject to a blind SQL injection vulnerability, where authenticated API key holders can exploit an unvalidated direction value in the orderBy query parameter of the tag statistics endpoint. This oversight enables attackers to inject arbitrary SQL fragments into a Doctrine QueryBuilder ORDER BY clause. By crafting specific malicious strings, attackers can extract sensitive information such as URLs, visitor records, IP addresses, geolocation data, user agents, and hashed API key secrets, impacting any user of the Shlink service. The potential for data breach necessitates immediate attention to secure the integration across affected instances.
Affected Version(s)
Shlink 3.3.1 <= 5.1.5
