CVE-2026-108594 | mealie-recipes Mealie up to 3.28.0 OpenID Connect Avatar Fetch server-side request forgery
A vulnerability identified as problematic has been detected in mealie-recipes Mealie up to 3.28.0. The affected element is an unknown function of the component OpenID Connect Avatar Fetch. This manipulation causes server-side request forgery.
This vulnerability is tracked as CVE-2026-108594. The attack is possible to be carried out remotely. No exploit exists.VulDB Recent EntriesRead More