CVE-2026-61520

Source
https://cve.org/CVERecord?id=CVE-2026-61520
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-61520.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-61520
Published
2026-07-14T20:17:15.901Z
Modified
2026-07-17T03:42:00.652323001Z
Severity
  • 6.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N CVSS Calculator
Summary
Simple Machines Forum SSRF via image proxy
Details

Simple Machines Forum 2.1 prior to commit 4bf35cf and 3.0 prior to commit b4d23df contains a server-side request forgery vulnerability in the image proxy that allows authenticated attackers to trigger internal HTTP requests by embedding attacker-controlled URLs in BBCode image tags, which the proxy fetches without validating resolved destination IPs against private address ranges, loopback, or link-local addresses. Attackers can leverage SMF's automatic HMAC signature generation for any embedded image URL to obtain valid signed proxy requests targeting internal services such as cloud instance metadata endpoints, internal web applications, and container network services.

Database specific
{
    "cwe_ids": [
        "CWE-918"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/61xxx/CVE-2026-61520.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "b4d23dfd74a511587c605f9d294cefc3a75b4b26"
                },
                {
                    "last_affected": "b4d23dfd74a511587c605f9d294cefc3a75b4b26"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ],
    "cna_assigner": "VulnCheck"
}
References

Affected packages

Git / github.com/simplemachines/smf

Affected ranges

Type
GIT
Repo
https://github.com/simplemachines/smf
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "2.1.0"
        },
        {
            "fixed": "2.1.7"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v2.*
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.1.7
v3.*
v3.0-alpha.1
v3.0-alpha.2
v3.0-alpha.3
v3.0-alpha.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-61520.json"