CVE-2026-57232 | Contao up to 5.3.47/5.7.8 Feed Reader FeedReaderController.php getResponse url server-side request forgery

SecurityVulns

A vulnerability was found in Contao up to 5.3.47/5.7.8. It has been declared as problematic. This affects the function FeedReaderController::getResponse of the file core-bundle/src/Controller/FrontendModule/FeedReaderController.php of the component Feed Reader. Such manipulation of the argument url leads to server-side request forgery.

This vulnerability is listed as CVE-2026-57232. The attack may be performed from remote. There is no available exploit.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More