Server-Side Request Forgery Vulnerability in Indico Event Management System
CVE-2026-25738

6.9MEDIUM

Key Information:

Vendor

Indico

Status
Vendor
CVE Published:
19 February 2026

What is CVE-2026-25738?

Indico, an event management system utilizing Flask-Multipass for multi-backend authentication, is susceptible to a server-side request forgery (SSRF). This vulnerability affects Indico versions prior to 3.3.10, allowing unauthorized requests to user-provided URLs, which could potentially target sensitive endpoints, including localhost or cloud metadata services. Although such features are integral to Indico's functionality, users must exercise caution. Specifically, only event organizers can trigger SSRF risks. For those hosting Indico in environments without publicly exposed sensitive data, the risk remains low. Users are advised to upgrade to version 3.3.10 to secure their systems and consider using proxy-related environment variables (http_proxy, https_proxy) for additional safety measures.

Affected Version(s)

indico < 3.3.10

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.