Open Source CMS Feed Reader Vulnerability in Contao by Contao
CVE-2026-57232

3.1LOW

Key Information:

Vendor

Contao

Status
Vendor
CVE Published:
31 July 2026

What is CVE-2026-57232?

The Contao CMS's Feed Reader module is vulnerable due to insufficient validation of RSS feed URLs passed to the HTTP client. This flaw allows authenticated backend users with editing permissions to send requests to internal network resources, potentially exposing sensitive information through unauthorized access to internal services or cloud metadata endpoints. The issue arises because no validation is enforced on the provided URLs, permitting unrestricted access paths. This vulnerability is addressed in version 5.3.48.

Affected Version(s)

contao >= 5.7.0-RC1, < 5.7.9 < 5.7.0-RC1, 5.7.9

contao >= 5.3.35, < 5.3.48 < 5.3.35, 5.3.48

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.