Server-Side Request Forgery in Friendica Affects Authenticated Users
CVE-2026-72597

6.5MEDIUM

Key Information:

Vendor

Friendica

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-72597?

A server-side request forgery vulnerability exists in Friendica through the 2026.08-dev branch. This flaw permits authenticated users with self-registered accounts to exploit the link-preview endpoint, which indiscriminately fetches user-supplied URLs. Due to the lack of an internal IP deny list, this vulnerability enables attackers to probe internal network services or gain unauthorized access to cloud metadata services. Protecting against such vulnerabilities is crucial to safeguard network integrity.

Affected Version(s)

Friendica 0 <= 2026.08-dev

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bobur Abdugafforov
.