CVE-2026-49262

Source
https://cve.org/CVERecord?id=CVE-2026-49262
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-49262.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-49262
Aliases
Published
2026-08-12T14:04:09.179Z
Modified
2026-08-14T04:03:52.348694017Z
Severity
  • 3.0 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N CVSS Calculator
Summary
Aimeos Pagible CMS vulnerable to Server Side Request Forgery (SSRF) via DNS rebinding in admin proxy
Details

In the Aimeos Pagible content management system prior to version 0.10.4, the administrative proxy route (cmsproxy) is vulnerable to a Server-Side Request Forgery (SSRF) attack via DNS Rebinding. A Time-of-Check to Time-of-Use (TOCTOU) race condition exists between the URL validation phase and the actual HTTP request phase, allowing attackers to access internal network resources and cloud metadata endpoints. Version 0.10.4 fixes the issue.

Database specific
{
    "cwe_ids": [
        "CWE-367",
        "CWE-918"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/49xxx/CVE-2026-49262.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/aimeos/pagible

Affected ranges

Type
GIT
Repo
https://github.com/aimeos/pagible
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "0.10.4"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

0.*
0.10.0
0.10.1
0.10.2
0.10.3
0.5
0.7.0
0.8.0
0.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-49262.json"