URL Validation Bypass in Statamic CMS by Statamic
CVE-2026-45660

5.4MEDIUM

Key Information:

Vendor

Statamic

Status
Vendor
CVE Published:
29 May 2026

What is CVE-2026-45660?

Statamic, a content management system built on Laravel and Git, has a vulnerability that enables unauthorized users to bypass the Glide image proxy's URL validation. This occurs due to improper normalization of IP representations before executing public-IP checks. Attackers can exploit this flaw to make the server issue HTTP requests to internal addresses, including private networks and cloud metadata endpoints, thereby posing a risk to data integrity and server security. Websites that allow users to provide URLs to Glide are particularly vulnerable. It's important to upgrade to versions 5.73.22 or 6.18.1 to mitigate this risk. Those running PHP 8.3 or newer are unaffected.

Affected Version(s)

cms < 5.73.22 < 5.73.22

cms >= 6.0.0-alpha.1, < 6.18.1 < 6.0.0-alpha.1, 6.18.1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.