Server-Side Request Forgery in FlaskBB Forum Software by Flask
CVE-2026-46556

6.5MEDIUM

Key Information:

Vendor

Flaskbb

Status
Vendor
CVE Published:
21 July 2026

What is CVE-2026-46556?

FlaskBB, a popular forum software built on the Flask micro framework, has a vulnerability that allows authenticated users to exploit the get_image_info() function to perform Server-Side Request Forgery. This flaw enables attackers to send HTTP requests to internal endpoints, potentially accessing sensitive internal services, including cloud metadata. The issue is classified as a blind SSRF due to its capacity for internal port scanning and triggering internal APIs. Users are advised to upgrade to version 2.2.1 or later to mitigate this risk.

Affected Version(s)

flaskbb < 2.2.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.