
CVE-2026-36759 A Server-Side Request Forgery (SSRF) in the /themes/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a … https://www.cve.org/CVERecord?id=CVE-2026-36759
Post summary
The post discloses a Server‑Side Request Forgery vulnerability in Halo v2.22.14 that allows authenticated attackers to probe internal resources, without mentioning PoC, exploitation tools, or patches.


