CVE-2026-32096Disclosure(useplunk / plunk)

LOWCVSS 8.6 · HIGH

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Patch useplunk plunk systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Plunk is an open-source email platform built on top of AWS SES. Prior to 0.7.0, a Server-Side Request Forgery (SSRF) vulnerability existed in the SNS webhook handler. An unauthenticated attacker could send a crafted request that caused the server to make an arbitrary outbound HTTP GET request to any host accessible from the server. This vulnerability is fixed in 0.7.0.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • plunk

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
plunk

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-11: 3PoC Mentioned / Linked · 2026-03-11: 1Patch / Workaround · 2026-03-11: 1Technical Details · 2026-03-11: 303-11
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-32096 Plunk is an open-source email platform built on top of AWS SES. Prior to 0.7.0, a Server-Side Request Forgery (SSRF) vulnerability existed in the SNS webhook handler.… https://www.cve.org/CVERecord?id=CVE-2026-32096

    Post summary

    CVE‑2026‑32096 describes a SSRF vulnerability in Plunk’s SNS webhook handler that existed before version 0.7.0; no PoC, exploit, patch, or active exploitation is mentioned.

    00000153
    56.6K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-32096: CRITICAL] Cybersecurity alert: Plunk email platform on AWS SES had SSRF vulnerability pre-0.7.0 version in SNS webhook handler. Update to version 0.7.0 for fix against unauthenticated attacks.#cve,CVE-2026-32096,#cybersecurity https://cvefind.com/CVE-2026-32096

    Post summary

    The alert highlights a critical SSRF flaw in Plunk’s SES integration, recommending an immediate update to version 0.7.0 for remediation.

    0000051
    600 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-32096: Plunk has SSRF via unvalidated A... Unauthenticated SSRF through AWS SNS webhook lets attackers pivot into internal networks via crafted SubscriptionConfir... https://zerodaysignal.com/vulnerability/CVE-2026-32096 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    Plunk’s AWS SNS webhook contains an unauthenticated SSRF flaw that can be used to pivot into internal networks; the vulnerability is disclosed with technical details but no active exploitation or patch is reported.

    0000072
    143 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appuseplunkplunk---

Explore more