A vulnerability was detected in October CMS up to 4.3.4. This affects the function...
zetlyn/cve-ghsa vulnerability ghsa GHSA-43c9-ch4w-3vh5 cve CVE-2026-101005 known 2026-09-28
https://github.com/advisories/GHSA-43c9-ch4w-3vh5
Properties
| cvss | 7.3receipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2026-101005",
"cvss": {
"score": 7.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_severities": {
"cvss_v3": {
"score": 7.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_v4": {
"score": 5.5,
"vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"cwes": [
{
"cwe_id": "CWE-918",
"name": "Server-Side Request Forgery (SSRF)"
}
],
"description": "A vulnerability was detected in October CMS up to 4.3.4. This affects the function validateExternalImageHost of the file System/Classes/ResizeImages.php of the component SSRF Protection. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit is now public and may be used. Upgrading to version 4.3.5 is able to mitigate this issue. You should upgrade the affected component.",
"epss": {
"percentage": 0.00298,
"percentile": 0.20145
},
"ghsa_id": "GHSA-43c9-ch4w-3vh5",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-43c9-ch4w-3vh5",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-43c9-ch4w-3vh5"
},
{
"type": "CVE",
"value": "CVE-2026-101005"
}
],
"nvd_published_at": "2026-09-28T07:17:19Z",
"published_at": "2026-09-28T09:30:25Z",
"references": [
"https://github.com/octobercms/october/security/advisories/GHSA-j2j7-7m99-6226",
"https://nvd.nist.gov/vuln/detail/CVE-2026-101005",
"https://github.com/0xGenesi/CVE/blob/main/October_CMS_SSRF_IPv6_Mapped_IPv4_Bypass.md",
"https://github.com/octobercms/october/releases/tag/v4.3.5",
"https://vuldb.com/cve/CVE-2026-101005",
"https://vuldb.com/submit/922294",
"https://vuldb.com/vuln/410875",
"https://vuldb.com/vuln/410875/cti",
"https://www.cybersecurity-help.cz/vdb/vulns/149488",
"https://github.com/advisories/GHSA-43c9-ch4w-3vh5"
],
"repository_advisory_url": null,
"severity": "medium",
"source_code_location": "",
"summary": "A vulnerability was detected in October CMS up to 4.3.4. This affects the function...",
"type": "unreviewed",
"updated_at": "2026-09-28T09:30:33Z",
"url": "https://api.github.com/advisories/GHSA-43c9-ch4w-3vh5",
"vulnerabilities": [],
"withdrawn_at": null
} |
|---|---|
| cwe | CWE-918receipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2026-101005",
"cvss": {
"score": 7.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_severities": {
"cvss_v3": {
"score": 7.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_v4": {
"score": 5.5,
"vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"cwes": [
{
"cwe_id": "CWE-918",
"name": "Server-Side Request Forgery (SSRF)"
}
],
"description": "A vulnerability was detected in October CMS up to 4.3.4. This affects the function validateExternalImageHost of the file System/Classes/ResizeImages.php of the component SSRF Protection. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit is now public and may be used. Upgrading to version 4.3.5 is able to mitigate this issue. You should upgrade the affected component.",
"epss": {
"percentage": 0.00298,
"percentile": 0.20145
},
"ghsa_id": "GHSA-43c9-ch4w-3vh5",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-43c9-ch4w-3vh5",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-43c9-ch4w-3vh5"
},
{
"type": "CVE",
"value": "CVE-2026-101005"
}
],
"nvd_published_at": "2026-09-28T07:17:19Z",
"published_at": "2026-09-28T09:30:25Z",
"references": [
"https://github.com/octobercms/october/security/advisories/GHSA-j2j7-7m99-6226",
"https://nvd.nist.gov/vuln/detail/CVE-2026-101005",
"https://github.com/0xGenesi/CVE/blob/main/October_CMS_SSRF_IPv6_Mapped_IPv4_Bypass.md",
"https://github.com/octobercms/october/releases/tag/v4.3.5",
"https://vuldb.com/cve/CVE-2026-101005",
"https://vuldb.com/submit/922294",
"https://vuldb.com/vuln/410875",
"https://vuldb.com/vuln/410875/cti",
"https://www.cybersecurity-help.cz/vdb/vulns/149488",
"https://github.com/advisories/GHSA-43c9-ch4w-3vh5"
],
"repository_advisory_url": null,
"severity": "medium",
"source_code_location": "",
"summary": "A vulnerability was detected in October CMS up to 4.3.4. This affects the function...",
"type": "unreviewed",
"updated_at": "2026-09-28T09:30:33Z",
"url": "https://api.github.com/advisories/GHSA-43c9-ch4w-3vh5",
"vulnerabilities": [],
"withdrawn_at": null
} |
| severity | mediumreceipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2026-101005",
"cvss": {
"score": 7.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_severities": {
"cvss_v3": {
"score": 7.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_v4": {
"score": 5.5,
"vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"cwes": [
{
"cwe_id": "CWE-918",
"name": "Server-Side Request Forgery (SSRF)"
}
],
"description": "A vulnerability was detected in October CMS up to 4.3.4. This affects the function validateExternalImageHost of the file System/Classes/ResizeImages.php of the component SSRF Protection. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit is now public and may be used. Upgrading to version 4.3.5 is able to mitigate this issue. You should upgrade the affected component.",
"epss": {
"percentage": 0.00298,
"percentile": 0.20145
},
"ghsa_id": "GHSA-43c9-ch4w-3vh5",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-43c9-ch4w-3vh5",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-43c9-ch4w-3vh5"
},
{
"type": "CVE",
"value": "CVE-2026-101005"
}
],
"nvd_published_at": "2026-09-28T07:17:19Z",
"published_at": "2026-09-28T09:30:25Z",
"references": [
"https://github.com/octobercms/october/security/advisories/GHSA-j2j7-7m99-6226",
"https://nvd.nist.gov/vuln/detail/CVE-2026-101005",
"https://github.com/0xGenesi/CVE/blob/main/October_CMS_SSRF_IPv6_Mapped_IPv4_Bypass.md",
"https://github.com/octobercms/october/releases/tag/v4.3.5",
"https://vuldb.com/cve/CVE-2026-101005",
"https://vuldb.com/submit/922294",
"https://vuldb.com/vuln/410875",
"https://vuldb.com/vuln/410875/cti",
"https://www.cybersecurity-help.cz/vdb/vulns/149488",
"https://github.com/advisories/GHSA-43c9-ch4w-3vh5"
],
"repository_advisory_url": null,
"severity": "medium",
"source_code_location": "",
"summary": "A vulnerability was detected in October CMS up to 4.3.4. This affects the function...",
"type": "unreviewed",
"updated_at": "2026-09-28T09:30:33Z",
"url": "https://api.github.com/advisories/GHSA-43c9-ch4w-3vh5",
"vulnerabilities": [],
"withdrawn_at": null
} |
Text
A vulnerability was detected in October CMS up to 4.3.4. This affects the function...
A vulnerability was detected in October CMS up to 4.3.4. This affects the function validateExternalImageHost of the file System/Classes/ResizeImages.php of the component SSRF Protection. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit is now public and may be used. Upgrading to version 4.3.5 is able to mitigate this issue. You should upgrade the affected component.