PSA-2026-04-PY6VCVE-2025-53641GCVE-125-2026-04-PY6VApril 19, 2026
8.2 High

Header mutation in middleware facilitates SSRF

Header mutation in middleware facilitates SSRF

Affected (1)

  • gitroomhqpostiz-app
    • ≥ 0Fixed in 1.62.3Affected

    All other versions: Unaffected

Overview

A vulnerability has been identified in the Postiz frontend application that allows an attacker to inject arbitrary HTTP headers into the middleware pipeline. This flaw enables a server-side request forgery (SSRF) condition, which can be exploited to initiate unauthorized outbound requests from the server hosting the Postiz application.

Severity

CVSS v3
8.2 High
8.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None

Weaknesses (1)

References (2)

Credits (3)

  • Dominik Prodinger
    Reporter · @prdngr
  • Enno Gelhaus
    Coordinator · @egelhaus
  • Nevo David
    Remediation developer · @nevo-david