CVE-2026-33693General

LOWCVSS 6.5 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.7.0-beta.9, the `v4_is_invalid()` function in `activitypub-federation-rust` (`src/utils.rs`) does not check for `Ipv4Addr::UNSPECIFIED` (0.0.0.0). An unauthenticated attacker controlling a remote domain can point it to 0.0.0.0, bypass the SSRF protection introduced by the fix for CVE-2025-25194 (GHSA-7723-35v7-qcxw), and reach localhost services on the target server. Version 0.7.0-beta.9 patches the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 3 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-03-27)
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-24: 1Mentions · 2026-03-27: 3Patch / Workaround · 2026-03-27: 1Technical Details · 2026-03-27: 203-2403-27
Signal classification2 categories
General
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-241
General1
2026-03-273
General2Patch1
Full discourse4 posts
  • CVE@CVEnew
    General

    CVE-2026-33693 Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.7.0-beta.9, the `v4_is_invalid()` function in `activitypub-federation-rust` (`src/utils.rs`… https://www.cve.org/CVERecord?id=CVE-2026-33693

    Post summary

    The post simply notes that CVE-2026-33693 affects Lemmy’s `v4_is_invalid()` function before version 0.7.0‑beta.9, but offers no additional context or actionable information.

    00010130
    56.9K followersView on X
  • Fernando Karl@fernandokarl
    Patch

    🚨 Atenção, profissionais de cibersegurança! A vulnerabilidade CVE-2026-33693 no Lemmy permite que atacantes contornem proteções SSRF ao apontar domínio para 0.0.0.0. Atualize para a versão 0.7.0-beta.9 e configure seu firewall! 🔒 #CyberSecurity #Vulnerability #CVE2026

    Post summary

    CVE‑2026‑33693 is an SSRF bypass vulnerability in Lemmy that can be exploited by pointing domain resolution to 0.0.0.0; administrators are urged to upgrade to 0.7.0‑beta.9 and configure firewalls to mitigate the issue.

    0000042
    260 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-33693 📊 Severity: 6.5 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-33693 #CVE-2026-33693 #CVE #Medium #CyberSecurity #InfoSec https://t.co/45hbzQzJm8

    Post summary

    The tweet announces CVE-2026-33693 with a 6.5 severity score and links to the NVD page but provides no PoC, exploit details, or mitigation information.

    0000027
    123 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-33693 CVE-2026-33693 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33693 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet merely cites CVE-2026-33693 and links to Vulmon for details, without providing any PoC, exploit code, active exploitation evidence, patch information, or technical specifics.

    0000038
    4.0K followersView on X

Explore more