SSRF Vulnerability in Wallos Personal Subscription Tracker
CVE-2026-77351

3.5LOW

Key Information:

Vendor

Ellite

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-77351?

Wallos, an open-source personal subscription tracker, contains a vulnerability that allows any authenticated user to store arbitrary SMTP hosts in their email notification settings without proper server-side validation. This oversight permits low-privileged attackers to craft malicious SMTP hosts leading to unwanted outbound connections from the Wallos server. The implications of this vulnerability are significant, as it could allow attackers to probe internal network services, potentially exposing sensitive data or systems. The issue is resolved in version 5.0.0, where appropriate validation measures have been implemented.

Affected Version(s)

Wallos < 5.0.0

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.