Blind SQL Injection in Shlink API by Shlink.io
CVE-2026-18737

7.1HIGH

Key Information:

Vendor

Shlinkio

Status
Vendor
CVE Published:
3 August 2026

What is CVE-2026-18737?

Shlink is subject to a blind SQL injection vulnerability, where authenticated API key holders can exploit an unvalidated direction value in the orderBy query parameter of the tag statistics endpoint. This oversight enables attackers to inject arbitrary SQL fragments into a Doctrine QueryBuilder ORDER BY clause. By crafting specific malicious strings, attackers can extract sensitive information such as URLs, visitor records, IP addresses, geolocation data, user agents, and hashed API key secrets, impacting any user of the Shlink service. The potential for data breach necessitates immediate attention to secure the integration across affected instances.

Affected Version(s)

Shlink 3.3.1 <= 5.1.5

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Theodosis Paidakis
.