CVE-2026-24736Disclosure(squidex.io / squidex)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Squidex is an open source headless content management system and content management hub. Versions of the application up to and including 7.21.0 allow users to define "Webhooks" as actions within the Rules engine. The url parameter in the webhook configuration does not appear to validate or restrict destination IP addresses. It accepts local addresses such as 127.0.0.1 or localhost. When a rule is triggered (Either manual trigger by manually calling the trigger endpoint or by a content update or any other triggers), the backend server executes an HTTP request to the user-supplied URL. Crucially, the server logs the full HTTP response in the rule execution log (lastDump field), which is accessible via the API. Which turns a "Blind" SSRF into a "Full Read" SSRF. As of time of publication, no patched versions are available.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • squidex

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-01-27); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
squidex

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-01-27: 3Mentions · 2026-01-28: 1Technical Details · 2026-01-27: 1Technical Details · 2026-01-28: 101-2701-28
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-01-273
Disclosure2General1
2026-01-281
Disclosure1
Full discourse4 posts
  • PulsePatch.io@pulsepatchio
    Disclosure

    Squidex has an SSRF vulnerability (CVE-2026-24736) in its webhook configuration. Review network egress and webhook validation #Squidex #SSRF #infosec https://www.pulsepatch.io/posts/cve-2026-24736-squidex-ssrf

    Post summary

    The post reveals an SSRF flaw (CVE-2026-24736) in Squidex’s webhook settings and urges users to review network egress and webhook validation.

    0000053
    1 followersView on X
  • The Hacker Wire@TheHackerWire
    General

    🔴 CVE-2026-24736 - Critical Squidex is an open source headless content management system and content management hub. Versions of the application up to and including 7.21.0 allow users to define "Webhooks" as actions... https://www.thehackerwire.com/vulnerability/CVE-2026-24736/ https://t.co/eRIgg3Q8cK

    Post summary

    The snippet announces CVE‑2026‑24736 as a critical issue affecting Squidex up to version 7.21.0, but it provides no technical details, exploit information, or mitigation guidance.

    0000049
    113 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24736 Squidex is an open source headless content management system and content management hub. Versions of the application up to and including 7.21.0 allow users to define … https://www.cve.org/CVERecord?id=CVE-2026-24736

    Post summary

    The passage identifies CVE‑2026‑24736 as affecting Squidex up to version 7.21.0 and links to the CVE record, but offers no additional exploitation, patch, or technical details.

    00000220
    56.5K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-24736: Squidex has Server-Side Request ... Squidex's webhook SSRF transforms from blind to full-read via response logging in rule execution dumps - perfect for in... https://zerodaysignal.com/vulnerability/CVE-2026-24736 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A new SSRF vulnerability (CVE‑2026‑24736) in Squidex’s webhook system allows attackers to read full internal responses through response logging, as disclosed on ZeroDaySignal.

    0000081
    132 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsquidex.iosquidex---

Explore more