
CVE-2026-27023 Twenty is an open source CRM. Prior to version 1.18, the SSRF protection in SecureHttpClientService validated request URLs at the request level but did not validate r… https://www.cve.org/CVERecord?id=CVE-2026-27023
Post summary
The CVE-2026-27023 vulnerability is an SSRF issue in an open-source CRM, addressed by the release of version 1.18; the post provides technical details but no exploitation or PoC information.
