VYPR
High severity8.2NVD Advisory· Published Apr 10, 2026· Updated Apr 14, 2026

CVE-2026-40168

CVE-2026-40168

Description

Postiz is an AI social media scheduling tool. Prior to 2.21.5, the /api/public/stream endpoint is vulnerable to SSRF. Although the application validates the initially supplied URL and blocks direct private/internal hosts, it does not re-validate the final destination after HTTP redirects. As a result, an attacker can supply a public HTTPS URL that passes validation and then redirects the server-side request to an internal resource.

Affected products

1
  • cpe:2.3:a:gitroom:postiz:*:*:*:*:*:*:*:*
    Range: <2.21.5

Patches

1

Vulnerability mechanics

Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

3

News mentions

0

No linked articles in our index yet.