CVE-2026-42194: Admidio has an incomplete fix for CVE-2026-32812 (SSRF)
(updated )
The incomplete SSRF fix in Admidio’s fetch_metadata.php validates the resolved IP address but passes the original hostname-based URL to curl_init(), leaving a DNS rebinding TOCTOU window that allows redirecting requests to internal IPs.
References
- github.com/Admidio/admidio
- github.com/Admidio/admidio/commit/f6b7a966abe4d75e9f707d665d7b4b5570e3185a
- github.com/Admidio/admidio/releases/tag/v5.0.9
- github.com/Admidio/admidio/security/advisories/GHSA-6j68-gcc3-mq73
- github.com/Admidio/admidio/security/advisories/GHSA-hcjj-chvw-fmw9
- github.com/advisories/GHSA-hcjj-chvw-fmw9
- nvd.nist.gov/vuln/detail/CVE-2026-42194
Code Behaviors & Features
Detect and mitigate CVE-2026-42194 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →