URL Validation Bypass in Statamic CMS by Statamic
CVE-2026-45660
What is CVE-2026-45660?
Statamic, a content management system built on Laravel and Git, has a vulnerability that enables unauthorized users to bypass the Glide image proxy's URL validation. This occurs due to improper normalization of IP representations before executing public-IP checks. Attackers can exploit this flaw to make the server issue HTTP requests to internal addresses, including private networks and cloud metadata endpoints, thereby posing a risk to data integrity and server security. Websites that allow users to provide URLs to Glide are particularly vulnerable. It's important to upgrade to versions 5.73.22 or 6.18.1 to mitigate this risk. Those running PHP 8.3 or newer are unaffected.
Affected Version(s)
cms < 5.73.22 < 5.73.22
cms >= 6.0.0-alpha.1, < 6.18.1 < 6.0.0-alpha.1, 6.18.1
