Server-Side Request Forgery Vulnerability in Linkwarden by Linkwarden
CVE-2026-44313

9.1CRITICAL

Key Information:

Vendor

Linkwarden

Vendor
CVE Published:
8 May 2026

What is CVE-2026-44313?

Linkwarden, a self-hosted open-source collaborative bookmark manager, contains a Server-Side Request Forgery (SSRF) vulnerability in its fetchTitleAndHeaders function. This vulnerability allows authenticated users to perform arbitrary HTTP requests to internal services due to inadequate URL validation that only verifies schema prefixes like 'http://' or 'https://'. This can potentially expose sensitive internal resources. The issue has been rectified in version 2.13.0.

Affected Version(s)

linkwarden < 2.13.0

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.