CVE-2026-33953Disclosure(linkace / linkace)

LOWCVSS 8.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linkace linkace systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

LinkAce is a self-hosted archive to collect website links. Versions prior to 2.5.3 block direct requests to private IP literals, but still performs server-side requests to internal-only resources when those resources are referenced through an internal hostname. This allows an authenticated user to trigger server-side requests to internal services reachable by the LinkAce server but not directly reachable by an external user. Version 2.5.3 patches the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linkace

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-27); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
linkace

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-27: 2Mentions · 2026-03-28: 1Patch / Workaround · 2026-03-27: 1Technical Details · 2026-03-27: 2Technical Details · 2026-03-28: 103-2703-28
Signal classification3 categories
Disclosure
133.3%
Patch
133.3%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-272
Disclosure1Patch1
2026-03-281
General1
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-33953 LinkAce is a self-hosted archive to collect website links. Versions prior to 2.5.3 block direct requests to private IP literals, but still performs server-side reques… https://www.cve.org/CVERecord?id=CVE-2026-33953

    Post summary

    The snippet notes a CVE affecting LinkAce, pointing to a server‑side request issue but provides no PoC, exploit, or patch details.

    0000082
    56.9K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-33953 - High LinkAce is a self-hosted archive to collect website links. Versions prior to 2.5.3 block direct requests to private IP literals, but still performs server-side requests to internal-only resou... https://www.thehackerwire.com/vulnerability/CVE-2026-33953/ https://t.co/3XIt7hTPXD

    Post summary

    An article discloses a high‑severity vulnerability in LinkAce (versions before 2.5.3) that still permits server‑side requests to internal resources even though direct requests to private IPs are blocked.

    0000042
    163 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33953: HIGH] LinkAce versions prior to 2.5.3 have a security flaw allowing authenticated users to trigger server-side requests to internal services. Update to version 2.5.3 for a patch.#cve,CVE-2026-33953,#cybersecurity https://cvefind.com/CVE-2026-33953

    Post summary

    A high‑severity SSRF vulnerability in LinkAce prior to v2.5.3 allows authenticated users to trigger internal requests; a patch is available in version 2.5.3.

    0000035
    617 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinkacelinkace---

Explore more