CVE-2026-13603Disclosure

LOWCVSS 9.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The payment integration pretix-oppwa provides support for the payment providers VR Payment, Hobex, and potentially others based on Oppwa's technology. The integration of Oppwa, following their official documentation, includes a step where the user is redirected from the payment provider back to our system with a query parameter like ?resourcePath=/v1/checkouts/{checkoutId}/payment in the URL. Our system is then supposed to fetch the status of the transaction from the URL given by baseUrl + resourcePath. Our plugin pretix-oppwa did so insecurely by concatenating the parameter form the URL to the base domain of the API without further validation and, critically, without a / at the end of the baseUrl. Therefore, an attacker could inject a resourcePath argument in a way that causes pretix to call a different server instead. Since the request includes the access token (API key) of the Oppwa account, this would leak the access token, giving access to data contained in the payment provider's system. This is fixed with the release today by strictly validating the given API URL. After installing the update, we recommend asking your payment provider for a new access token and updating it in pretix.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-01: 1Patch / Workaround · 2026-07-01: 1Technical Details · 2026-07-01: 107-01
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - pretix-oppwa resourcePath URL concatenation SSRF (CVE-2026-13603) pretix-oppwa improperly concatenates an unvalidated resourcePath query parameter into the Oppwa API base URL when building outbound requests. The root cause is improper input validation leading to server-side request forgery (SSRF) via attacker-controlled URL/path manipulation. An attacker who can influence the resourcePath parameter can redirect the server’s request to an arbitrary destination, and the request is sent with the Oppwa access token (API key) attached. If exploited, this can leak payment-provider credentials and enable unauthorized access to sensitive payment data and downstream systems. 👉 Affected: pretix-oppwa (unpatched versions) | Upgrade to the vendor patched release (fixed by API URL validation)

    Post summary

    CVE‑2026‑13603 is an SSRF flaw in pret‑ix‑oppwa caused by concatenating an unvalidated resourcePath, allowing attackers to send authenticated requests to arbitrary URLs; the vendor has addressed the issue with a patch that validates the API URL.

    0000065
    232 followersView on X

Explore more