
🚨 CRITICAL - pretix-oppwa resourcePath URL concatenation SSRF (CVE-2026-13603) pretix-oppwa improperly concatenates an unvalidated resourcePath query parameter into the Oppwa API base URL when building outbound requests. The root cause is improper input validation leading to server-side request forgery (SSRF) via attacker-controlled URL/path manipulation. An attacker who can influence the resourcePath parameter can redirect the server’s request to an arbitrary destination, and the request is sent with the Oppwa access token (API key) attached. If exploited, this can leak payment-provider credentials and enable unauthorized access to sensitive payment data and downstream systems. 👉 Affected: pretix-oppwa (unpatched versions) | Upgrade to the vendor patched release (fixed by API URL validation)
Post summary
CVE‑2026‑13603 is an SSRF flaw in pret‑ix‑oppwa caused by concatenating an unvalidated resourcePath, allowing attackers to send authenticated requests to arbitrary URLs; the vendor has addressed the issue with a patch that validates the API URL.
