Server-Side Request Forgery Vulnerability in Koha by Koha Community
CVE-2026-26379
6.5MEDIUM
What is CVE-2026-26379?
Koha software versions up to 25.11 have a vulnerability that allows authenticated attackers to exploit a Server-Side Request Forgery (SSRF) due to improper Z39.50/SRU server configuration. This flaw enables attackers to potentially conduct internal network scans, thereby revealing sensitive information about internal services by analyzing the response times from the server. It is crucial for users of affected Koha versions to review their configurations and apply necessary security measures.
