CVE-2026-3961General

LOWCVSS 2.1 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was determined in zyddnys manga-image-translator up to beta-0.3. The affected element is the function to_pil_image of the file manga-image-translator-main/server/request_extraction.py of the component Translate Endpoints. This manipulation causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-07-14)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-11: 1Mentions · 2026-07-14: 2Technical Details · 2026-03-11: 1Technical Details · 2026-07-14: 203-1107-14
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-03-111
Disclosure1
2026-07-142
General2
Full discourse3 posts
  • Geng Yang@geng_zast
    General

    `CVE-2026-3961` in `manga-image-translator` is not one SSRF. It is seven public SSRF reports merged into one CVE. That usually means the root problem is shared logic. https://t.co/Bjk8yaXm7j

    Post summary

    The tweet clarifies that CVE‑2026‑3961 aggregates seven SSRF incidents sharing common logic, providing no PoC, exploit, active exploitation, or patch information.

    1001048
    47 followersView on X
  • ZAST AI@zast_ai
    General

    Security note: `manga-image-translator <= beta-0.3` has seven verified SSRF reports merged into `CVE-2026-3961`. This is a class-level issue, not one missed route check. https://t.co/TlbBsLknJ1

    Post summary

    A brief disclosure that CVE-2026-3961 involves SSRF vulnerabilities in manga-image-translator <= beta‑0.3, but no further details are provided.

    1000057
    37 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3961 A vulnerability was determined in zyddnys manga-image-translator up to beta-0.3. The affected element is the function to_pil_image of the file manga-image-translator-ma… https://www.cve.org/CVERecord?id=CVE-2026-3961

    Post summary

    The post announces the discovery of CVE‑2026‑3961 in the to_pil_image function of zyddnys manga‑image‑translator up to beta‑0.3, highlighting the affected code without providing exploit or mitigation details.

    00000116
    56.7K followersView on X

Explore more