Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
CVE-2026-54491
  • github.com/koel/koel
Koel: Incomplete fix for CVE-2026-47260 — systemic SSRF in podcast & radio fetch paths 19 Aug
  • Fix available
  • Severity - 7.1 (High)
CVE-2026-54493
  • github.com/koel/koel
Koel: Authenticated Full-Read SSRF via Subsonic Internet Radio Stations 19 Aug
  • Fix available
  • Severity - 7.7 (High)
CVE-2026-54494
  • github.com/koel/koel
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4 19 Aug
  • Fix available
  • Severity - 5.3 (Medium)
CVE-2026-54492
  • github.com/koel/koel
Koel: Authenticated Blind SSRF via Subsonic Podcast Channel Creation 19 Aug
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-rjg7-r26h-cfp2
  • Packagist/phanan/koel
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4 15 Jul
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-jr4p-4xjh-fwvw
  • Packagist/phanan/koel
Koel: Server-Side Request Forgery (SSRF) in radio station creation due to missing validation bail 15 Jul
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-6qvr-wjmv-v8mm
  • Packagist/phanan/koel
Koel: Incomplete fix for CVE-2026-47260 — systemic SSRF in podcast & radio fetch paths 15 Jul
  • Fix available
  • Severity - 7.1 (High)
GHSA-8q6q-m837-fv64
  • Packagist/phanan/koel
Koel has SSRF through Authenticated Subsonic podcast feed URLs 15 Jul
  • Fix available
  • Severity - 6.4 (Medium)
GHSA-6p96-cfg5-4vhp
  • Packagist/phanan/koel
Koel: Authenticated Full-Read SSRF via Subsonic Internet Radio Stations 15 Jul
  • Fix available
  • Severity - 7.7 (High)
GHSA-w79m-f3jx-779v
  • Packagist/phanan/koel
Koel: Authenticated Blind SSRF via Subsonic Podcast Channel Creation 15 Jul
  • Fix available
  • Severity - 4.3 (Medium)
CVE-2026-50552
  • github.com/koel/koel
Koel: Server-Side Request Forgery (SSRF) in radio station creation due to missing validation bail 12 Jun
  • Fix available
  • Severity - 6.3 (Medium)
CVE-2026-47260
  • github.com/koel/koel
Koel Vulnerable to SSRF via Podcast Episode Enclosure URLs 12 Jun
  • Fix available
  • Severity - 7.7 (High)
GHSA-7j2f-6h2r-6cqc
  • Packagist/phanan/koel
Koel Vulnerable to SSRF via Podcast Episode Enclosure URLs 29 May
  • Fix available
  • Severity - 7.7 (High)
GHSA-r37h-j483-cjjm
  • Packagist/phanan/koel
Improper rate limiting in Koel 01 Jun 2021
  • Fix available
CVE-2021-33563
  • github.com/koel/koel
See record for full details 24 May 2021
  • Fix available
  • Severity - 7.5 (High)