CVE-2026-33182Disclosure(saloon / saloon)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Saloon is a PHP library that gives users tools to build API integrations and SDKs. Prior to version 4.0.0, when building the request URL, Saloon combined the connector's base URL with the request endpoint. If the endpoint was a valid absolute URL, the code used that URL as-is and ignored the base URL. The request—and any authentication headers, cookies, or tokens attached by the connector—was then sent to the attacker-controlled host. If the endpoint could be influenced by user input or configuration (e.g. redirect_uri, callback URL), this allowed server-side request forgery (SSRF) and/or credential leakage to a third-party host. The fix in version 4.0.0 is to reject absolute URLs in the endpoint: URLHelper::join() throws InvalidArgumentException when the endpoint is a valid absolute URL, unless explicitly allowed, requiring callers to opt-in to the functionality on a per-connector or per-request basis.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-522CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • saloon

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
saloon

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-26: 2Technical Details · 2026-03-26: 103-26
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CVE@CVEnew
    General

    CVE-2026-33182 Saloon is a PHP library that gives users tools to build API integrations and SDKs. Prior to version 4.0.0, when building the request URL, Saloon combined the connecto… https://www.cve.org/CVERecord?id=CVE-2026-33182

    Post summary

    The post simply references CVE-2026-33182 for the Saloon PHP library without providing additional details on the vulnerability, exploitation, or mitigation.

    00000110
    56.8K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-33182 - Saloon is vulnerable to SSRF and credential leakage via absolute URL in endpoint overriding base URL Intel Report: https://ift.tt/iJEmf8c

    Post summary

    The alert identifies CVE‑2026‑33182 as an SSRF/credential leakage issue in Saloon, but does not provide a PoC, exploit, patch, or evidence of active exploitation.

    0000034
    286 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsaloonsaloon---

Explore more