Server-Side Request Forgery Vulnerability in Indico Event Management System
CVE-2026-25738
What is CVE-2026-25738?
Indico, an event management system utilizing Flask-Multipass for multi-backend authentication, is susceptible to a server-side request forgery (SSRF). This vulnerability affects Indico versions prior to 3.3.10, allowing unauthorized requests to user-provided URLs, which could potentially target sensitive endpoints, including localhost or cloud metadata services. Although such features are integral to Indico's functionality, users must exercise caution. Specifically, only event organizers can trigger SSRF risks. For those hosting Indico in environments without publicly exposed sensitive data, the risk remains low. Users are advised to upgrade to version 3.3.10 to secure their systems and consider using proxy-related environment variables (http_proxy, https_proxy) for additional safety measures.
Affected Version(s)
indico < 3.3.10
