PSA-2026-04-PY6VCVE-2025-536412026-04-19
8.2 High

Header mutation in middleware facilitates SSRF

Header mutation in middleware facilitates SSRF

A vulnerability has been identified in the Postiz frontend application that allows an attacker to inject arbitrary HTTP headers into the middleware pipeline. This flaw enables a server-side request forgery (SSRF) condition, which can be exploited to initiate unauthorized outbound requests from the server hosting the Postiz application.