Server-Side Request Forgery Vulnerability in Karakeep Bookmark Application
CVE-2026-45082

7.6HIGH

Key Information:

Status
Vendor
CVE Published:
26 May 2026

What is CVE-2026-45082?

A Server-Side Request Forgery (SSRF) vulnerability was discovered in the Karakeep application, specifically affecting versions before 0.32.0. This vulnerability allows attackers to bypass existing protections designed to prevent unauthorized requests to internal or private network destinations. Through the exploitation of crafted HTTP redirect chains, an authenticated user can cause the application to make requests to internally available Docker network services. The vulnerability impacts various processing paths within the application, including components responsible for crawling and video download functionalities. A patch addressing this issue is available in version 0.32.0.

Affected Version(s)

karakeep < 0.32.0

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.