Carl Sampson[verified]@chsDisclosure
A newly disclosed SSRF vulnerability (CVE‑2026‑27696) in changedetection.io allows unauthenticated servers to retrieve AWS metadata through URL validation bypass, underscoring a TOCTOU flaw.
CVETodo[verified]@CveTodoDisclosure
The post announces a Server‑Side Request Forgery vulnerability (CVE‑2026‑27696) in changedetection.io versions before 0.54.1, detailing the flaw in URL validation and the affected function.
CRAC Learning - Tech@cracbotDisclosure
The post announces CVE-2026-27696 with a high CVSS score and affected versions, but provides no PoC, exploit, or patch details.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
A new SSRF vulnerability (CVE-2026-27696) affecting changedetection.io has been disclosed, with details available via Vulmon links.
CVE@CVEnewDisclosure
The post announces that versions of changedetection.io prior to 0.54.1 are vulnerable to Server‑Side Request Forgery, referencing the CVE record.
CVEFind.com@CveFindComPatch
The post highlights a high‑severity SSRF flaw in changedetection.io versions prior to 0.54.1 and recommends updating to 0.54.1 to mitigate the vulnerability.