Unrated severityNVD Advisory· Published Mar 5, 2026· Updated Mar 6, 2026
Twenty: SSRF protection bypass via HTTP redirect following in secure HTTP client
CVE-2026-27023
Description
Twenty is an open source CRM. Prior to version 1.18, the SSRF protection in SecureHttpClientService validated request URLs at the request level but did not validate redirect targets. An authenticated user who could control outbound request URLs (e.g., webhook endpoints, image URLs) could bypass private IP blocking by redirecting through an attacker-controlled server. This issue has been patched in version 1.18.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/twentyhq/twenty/releases/tag/v1.18.0mitrex_refsource_MISC
- github.com/twentyhq/twenty/security/advisories/GHSA-wm7q-rvq3-x8q9mitrex_refsource_CONFIRM
News mentions
12- [Guest Diary] New Malware Libraries means New Signatures, (Fri, May 15th)SANS Internet Storm Center · May 15, 2026
- 73 Seconds to Breach, 24 Hours to Patch: The Case for Autonomous ValidationBleepingComputer · May 13, 2026
- European countries are exporting surveillance tech to countries with poor human rights records, report saysThe Record · May 12, 2026
- The State of Ransomware – Q1 2026Check Point Research · May 11, 2026
- How Dark Reading Lifted Off the Launchpad in 2006Dark Reading · May 4, 2026
- Yet another experiment proves it's too damn simple to poison large language modelsThe Register Security · Apr 29, 2026
- 20-Year-Old Malware Rewrites History of Cyber SabotageDark Reading · Apr 27, 2026
- Medieval Encrypted Letter DecodedSchneier on Security · Apr 27, 2026
- PhantomRPC: A new privilege escalation technique in Windows RPCSecurelist · Apr 24, 2026
- FakeWallet crypto stealer spreading through iOS apps in the App StoreSecurelist · Apr 20, 2026
- Virtual machines, virtually everywhere – and with real security gapsESET WeLiveSecurity · Mar 25, 2026
- Operation Alice Takes Down 370,000+ Dark Web SitesInfosecurity Magazine · Mar 23, 2026