VYPR
Critical severity9.1NVD Advisory· Published Jun 15, 2026· Updated Jun 16, 2026

CVE-2026-50887

CVE-2026-50887

Description

A Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of shlink v5.0.1 allows attackers to scan internal resources via supplying a crafted longUrl.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
shlinkio/shlinkPackagist
<= 5.0.1

Affected products

2

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.