← voltar
CVE-2026-35461

Papra has a Blind Server-Side Request Forgery (SSRF) via Webhook URL

CVSS 5 MEDIUMEPSS 0.2%CWE-918
Vexday Risk Score
13Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 5EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
07 abr 2026Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, the Papra webhook system allows authenticated users to register arbitrary URLs as webhook endpoints with no validation of the destination address. The server makes outbound HTTP POST requests to registered URLs, including localhost, internal network ranges, and cloud provider metadata endpoints, on every document event. This vulnerability is fixed in 26.4.0.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Produtos afetados
papra-hq · papra

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →