Open Source CMS Feed Reader Vulnerability in Contao by Contao
CVE-2026-57232
3.1LOW
What is CVE-2026-57232?
The Contao CMS's Feed Reader module is vulnerable due to insufficient validation of RSS feed URLs passed to the HTTP client. This flaw allows authenticated backend users with editing permissions to send requests to internal network resources, potentially exposing sensitive information through unauthorized access to internal services or cloud metadata endpoints. The issue arises because no validation is enforced on the provided URLs, permitting unrestricted access paths. This vulnerability is addressed in version 5.3.48.
Affected Version(s)
contao >= 5.7.0-RC1, < 5.7.9 < 5.7.0-RC1, 5.7.9
contao >= 5.3.35, < 5.3.48 < 5.3.35, 5.3.48
