Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. aimeos/pagible
  4. ›
  5. CVE-2026-49262

CVE-2026-49262: Aimeos Pagible CMS vulnerable to Server Side Request Forgery (SSRF) via DNS rebinding in admin proxy

June 26, 2026

The administrative proxy route (cmsproxy) in Aimeos Pagible CMS is vulnerable to a Server-Side Request Forgery (SSRF) attack via DNS Rebinding. A Time-of-Check to Time-of-Use (TOCTOU) race condition exists between the URL validation phase and the actual HTTP request phase, allowing attackers to access internal network resources and cloud metadata endpoints.

References

  • github.com/advisories/GHSA-mmj8-wcvw-6789
  • github.com/aimeos/pagible/security/advisories/GHSA-mmj8-wcvw-6789
  • nvd.nist.gov/vuln/detail/CVE-2026-49262

Code Behaviors & Features

Detect and mitigate CVE-2026-49262 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 0.10.4

Fixed versions

  • 0.10.4

Solution

Upgrade to version 0.10.4 or above.

Impact 3 LOW

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition
  • CWE-918: Server-Side Request Forgery (SSRF)

Source file

packagist/aimeos/pagible/CVE-2026-49262.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Thu, 16 Jul 2026 12:17:54 +0000.