
CVE-2026-40168 Postiz is an AI social media scheduling tool. Prior to 2.21.5, the /api/public/stream endpoint is vulnerable to SSRF. Although the application validates the initially… https://www.cve.org/CVERecord?id=CVE-2026-40168
Post summary
CVE-2026-40168 targets Postiz’s /api/public/stream endpoint, causing an SSRF flaw that is remedied in version 2.21.5; no PoC or exploit details are disclosed.

