CVE-2026-27479Disclosure(wallosapp / wallos)

LOWCVSS 7.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Wallos is an open-source, self-hostable personal subscription tracker. Versions 4.6.0 and below contain a Server-Side Request Forgery (SSRF) vulnerability in the subscription and payment logo/icon upload functionality. The application validates the IP address of the provided URL before making the request, but allows HTTP redirects (CURLOPT_FOLLOWLOCATION = true), enabling an attacker to bypass the IP validation and access internal resources, including cloud instance metadata endpoints. The getLogoFromUrl() function validates the URL by resolving the hostname and checking if the resulting IP is in a private or reserved range using FILTER_FLAG_NO_PRIV_RANGE | FILTER_FLAG_NO_RES_RANGE. However, the subsequent cURL request is configured with CURLOPT_FOLLOWLOCATION = true and CURLOPT_MAXREDIRS = 3, which means the request will follow HTTP redirects without re-validating the destination IP. This issue has been fixed in version 4.6.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wallos

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-10); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
wallos

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-10: 1Mentions · 2026-03-23: 103-1003-23
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-101
Disclosure1
2026-03-231
General1
Full discourse2 posts
  • Albert @YZ9YT@yz9yt
    General

    @rez0__ I should to do a video of my 3 CVEs with a Bugtraceai framework for 2 dollars run. Wallos High: https://www.cve.org/CVERecord?id=CVE-2026-27479 ZoneMinder High: https://www.cve.org/CVERecord?id=CVE-2026-27470 Piwigo Medium: https://www.cve.org/CVERecord?id=CVE-2026-27834

    Post summary

    The tweet simply lists three CVE identifiers with links, without providing any proof‑of‑concept, exploitation details, patch information, or technical analysis.

    00001657
    1.3K followersView on X
  • Albert @YZ9YT@yz9yt
    Disclosure

    @carlosazaustre Y donde han puesto los CVEs que encontraron? yo te paso los que encontré con BugTraceAI Wallos - High https://www.cve.org/CVERecord?id=CVE-2026-27479 ZoneMinder - High https://www.cve.org/CVERecord?id=CVE-2026-27470 Piwigo (Pendiente de Disclosure) - High CVE-2026-27834

    Post summary

    The tweet announces three high‑severity CVEs discovered via BugTraceAI, providing links for two of them, and does not include PoC, exploit, or mitigation details.

    00010180
    1.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwallosappwallos---

Explore more