VYPR
Medium severity5.0NVD Advisory· Published Apr 7, 2026· Updated Apr 14, 2026

CVE-2026-35516

CVE-2026-35516

Description

LinkAce is a self-hosted archive to collect website links. Prior to 2.5.4, LinkRepository::update and CheckLinksCommand::checkLink do not check for private IPs. An authenticated user can read responses from internal services (AWS IMDSv1, cloud metadata, internal APIs) by creating a link with a public URL and then updating it to a private IP. The links:check cron job makes the request server-side without IP filtering. This can expose cloud credentials, internal service data, and network topology. This vulnerability is fixed in 2.5.4.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Linkace/Linkace2 versions
    cpe:2.3:a:linkace:linkace:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:linkace:linkace:*:*:*:*:*:*:*:*range: <2.5.4
    • (no CPE)range: <2.5.4

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.