CVE-2026-44313Disclosure

LOWCVSS 9.1 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. Prior to version 2.13.0, a Server-Side Request Forgery (SSRF) vulnerability in the fetchTitleAndHeaders function allows authenticated users to make arbitrary HTTP requests to internal services due to insufficient URL validation that only checks for "http://" or "https://" prefixes. This issue has been patched in version 2.13.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 7 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-05-14); latest day: 3
  • 9 total mentions across 4 days

Deep dive

Activity timeline9 mentions / 4d
01223Mentions · 2026-05-09: 2Mentions · 2026-05-10: 1Mentions · 2026-05-14: 3Mentions · 2026-06-11: 3Patch / Workaround · 2026-05-09: 1Technical Details · 2026-05-09: 2Technical Details · 2026-05-14: 2Technical Details · 2026-06-11: 305-0905-1005-1406-11
Signal classification3 categories
Disclosure
777.8%
Patch
111.1%
General
111.1%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-092
Disclosure1Patch1
2026-05-101
Disclosure1
2026-05-143
Disclosure2General1
2026-06-113
Disclosure3
Full discourse9 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    44313 is — The Metadata Proxy: Critical SSRF in Linkwarden Lets Authenticated Users Raid Internal Infrastructure. CVE-2026-44313 is a critical server-side request forgery (SSRF) vulnerability in Linkwarden, a popular open-source bookmark manager.

    Post summary

    The text announces the discovery of a critical SSRF vulnerability (CVE-2026-44313) in Linkwarden, with no additional details on exploitation or mitigation.

    1000041
    266 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-44313 is a critical server-side request forgery (SSRF) vulnerability in Linkwarden, a popular open-source bookmark manager. Authenticated users can force the server to make arbitrary HTTP requests to internal services, potentially exposing cloud metadata…

    Post summary

    The post announces the existence of a critical SSRF vulnerability in Linkwarden, outlining its impact but providing no PoC, exploit code, or patch information.

    1000040
    266 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Sources TheHackerWire: "Critical SSRF in Linkwarden (CVE-2026-44313)" (May 9, 2026) – TheHackerWire: CVE-2026-44313 Vulnerability Database – CVE-2026-44313 is a critical server-side request forgery (SSRF) vulnerability in Linkwarden, a popular open-source bookmark manager.

    Post summary

    A critical SSRF vulnerability, CVE‑2026‑44313, has been disclosed in the open‑source Linkwarden bookmark manager, with no PoC, exploit, or patch details provided.

    1000039
    266 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVSS 9.1 CRITICAL · CVE-2026-44313 · 9.1 → 2.13.0 CVE: CVE-2026-44313 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L Severity: CRITICAL Status: Critical advisory

    Post summary

    The entry details CVE‑2026‑44313 with a CVSS 9.1 rating and critical severity but provides no PoC, exploit, patch, or evidence of active exploitation.

    1000031
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-44313 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L Severity: CRITICAL Status: Critical advisory Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages.

    Post summary

    The snippet announces CVE‑2026‑44313 with a high CVSS score and critical severity, but it offers no PoC, exploit code, or patch details.

    1000047
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-44313-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided text lacks actionable or detailed information about CVE-2026-44313; it only references a URL and generic hashtags, making it impossible to determine specific aspects of the vulnerability.

    0000020
    210 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-44313 📊 Severity: 9.1 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-44313 #CVE-2026-44313 #CVE #Critical #CyberSecurity #InfoSec https://t.co/4faQ1hMWaG

    Post summary

    A new CVE‑2026‑44313 is announced with a critical 9.1 score, affecting unspecified products; no further technical, exploit, or patch details are supplied.

    0000059
    157 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-44313 Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. Prior to version 2.13.0, a Server-Side Request Forg… https://www.cve.org/CVERecord?id=CVE-2026-44313

    Post summary

    CVE‑2026‑44313 describes a Server‑Side Request vulnerability in Linkwarden before version 2.13.0, with the patch applied in that version.

    0000085
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-44313 Server-Side Request Forgery in Linkwarden Prior to Versio... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-44313 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The post references CVE‑2026‑44313, identifies it as a Server‑Side Request Forgery affecting Linkwarden before a certain version, and links to a vulnerability details page; it provides no PoC, exploit, active use, patch, or debunking information.

    0000045
    4.0K followersView on X

Explore more