The Glide image proxy's URL validation could be bypassed using an IP representation that wasn't normalized before the public-IP check. An unauthenticated user could cause the server to make HTTP requests to internal addresses — including loopback, private network, and cloud metadata endpoints.
This affects sites that pass user-supplied URLs to Glide. Sites running PHP 8.3 or newer are not affected.
This has been fixed in 5.73.22 and 6.18.1
{
"github_reviewed": true,
"github_reviewed_at": "2026-05-18T15:32:43Z",
"nvd_published_at": "2026-05-29T18:17:11Z",
"severity": "MODERATE",
"cwe_ids": [
"CWE-918"
]
}