CVE-2026-101005 | October CMS up to 4.3.4 SSRF Protection ResizeImages.php validateExternalImageHost server-side request forgery (GHSA-j2j7-7m99-6226)

SecurityVulns

A vulnerability, which was classified as critical, was found in October CMS up to 4.3.4. This affects the function validateExternalImageHost of the file System/Classes/ResizeImages.php of the component SSRF Protection. The manipulation results in server-side request forgery.

This vulnerability is cataloged as CVE-2026-101005. The attack may be launched remotely. Furthermore, there is an exploit available.

You should upgrade the affected component.VulDB Recent EntriesRead More