Server-Side Request Forgery Vulnerability in Serendipity by S9y
CVE-2026-73629

8.4HIGH

Key Information:

Vendor

S9y

Vendor
CVE Published:
13 August 2026

What is CVE-2026-73629?

Serendipity versions prior to 2.6.0 are vulnerable to a server-side request forgery attack due to improper filtering in the serendipity_url_allowed() function. This vulnerability allows authenticated users with specific permissions to submit requests to internal services, primarily by using hex-encoded IPv4 addresses and various formats of IPv6 literals. As a result, attackers can retrieve sensitive response bodies directly from the public uploads directory, potentially exposing critical internal data.

Affected Version(s)

Serendipity 0 < 2.6.0

Serendipity 2.6.0

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

riodrwn
.