SSRF Vulnerability in Wallos Subscription Tracker Affects Multiple Versions
CVE-2026-61638
8.2HIGH
What is CVE-2026-61638?
Wallos, an open-source personal subscription tracker, is affected by a Server-Side Request Forgery (SSRF) vulnerability due to inadequate validation of user input in the email notification endpoint. Prior to version 4.9.6, this endpoint did not properly validate the 'smtpaddress' and 'smtpport' parameters provided in POST requests. As a result, an authenticated user could exploit this weakness to send requests to internal network services or access cloud metadata, posing a significant risk to sensitive data. The issue has been addressed in version 4.9.6, where appropriate validations have been implemented to prevent such exploitation.
Affected Version(s)
Wallos < 4.9.6
