
CVE-2026-35516 Server-Side Request Forgery in LinkAce Prior to Version 2.5.4 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-35516
Post summary
The entry announces a Server‑Side Request Forgery vulnerability in LinkAce pre‑2.5.4.
Signal is active with 2 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
LinkAce is a self-hosted archive to collect website links. Prior to 2.5.4, LinkRepository::update and CheckLinksCommand::checkLink do not check for private IPs. An authenticated user can read responses from internal services (AWS IMDSv1, cloud metadata, internal APIs) by creating a link with a public URL and then updating it to a private IP. The links:check cron job makes the request server-side without IP filtering. This can expose cloud credentials, internal service data, and network topology. This vulnerability is fixed in 2.5.4.
Priority
LOW
Exploitation
NONE
PoC
YES
Patch
NONE
Momentum
NONE
If you run products in this scope, you should treat this CVE as relevant to your environment.

CVE-2026-35516 Server-Side Request Forgery in LinkAce Prior to Version 2.5.4 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-35516
Post summary
The entry announces a Server‑Side Request Forgery vulnerability in LinkAce pre‑2.5.4.

CVE-2026-35516 LinkAce is a self-hosted archive to collect website links. Prior to 2.5.4, LinkRepository::update and CheckLinksCommand::checkLink do not check for private IPs. An au… https://www.cve.org/CVERecord?id=CVE-2026-35516
Post summary
The snippet announces CVE‑2026‑35516, describing that LinkAce functions prior to version 2.5.4 do not validate private IPs, thereby revealing the vulnerability's nature without providing exploit evidence or patches.
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | linkace | linkace | - | - | - |