CVE-2026-82667 | yaojingang GEOFlow up to 2.1.0 GenericHttpEndpointResolver.php DistributionController.isValidHttpEndpoint endpoint_url server-side request forgery (Issue 60)

SecurityVulns

A vulnerability categorized as problematic has been discovered in yaojingang GEOFlow up to 2.1.0. Impacted is the function DistributionController.isValidHttpEndpoint of the file app/Services/GeoFlow/GenericHttpEndpointResolver.php. Such manipulation of the argument endpoint_url leads to server-side request forgery.

This vulnerability is referenced as CVE-2026-82667. It is possible to launch the attack remotely. Furthermore, an exploit is available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More