A vulnerability was detected in October CMS up to 4.3.4. This affects the function...

zetlyn/cve-ghsa vulnerability ghsa GHSA-43c9-ch4w-3vh5 cve CVE-2026-101005 known 2026-09-28

https://github.com/advisories/GHSA-43c9-ch4w-3vh5

Properties

cvss7.3
receipt
Source
GitHub advisories
Its words
7.3
Read by
field:cvss.score
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-06 13:46 UTC
Original
open at the source
What the source handed over
{
  "credits": [],
  "cve_id": "CVE-2026-101005",
  "cvss": {
    "score": 7.3,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 7.3,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
    },
    "cvss_v4": {
      "score": 5.5,
      "vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-918",
      "name": "Server-Side Request Forgery (SSRF)"
    }
  ],
  "description": "A vulnerability was detected in October CMS up to 4.3.4. This affects the function validateExternalImageHost of the file System/Classes/ResizeImages.php of the component SSRF Protection. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit is now public and may be used. Upgrading to version 4.3.5 is able to mitigate this issue. You should upgrade the affected component.",
  "epss": {
    "percentage": 0.00298,
    "percentile": 0.20145
  },
  "ghsa_id": "GHSA-43c9-ch4w-3vh5",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-43c9-ch4w-3vh5",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-43c9-ch4w-3vh5"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-101005"
    }
  ],
  "nvd_published_at": "2026-09-28T07:17:19Z",
  "published_at": "2026-09-28T09:30:25Z",
  "references": [
    "https://github.com/octobercms/october/security/advisories/GHSA-j2j7-7m99-6226",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-101005",
    "https://github.com/0xGenesi/CVE/blob/main/October_CMS_SSRF_IPv6_Mapped_IPv4_Bypass.md",
    "https://github.com/octobercms/october/releases/tag/v4.3.5",
    "https://vuldb.com/cve/CVE-2026-101005",
    "https://vuldb.com/submit/922294",
    "https://vuldb.com/vuln/410875",
    "https://vuldb.com/vuln/410875/cti",
    "https://www.cybersecurity-help.cz/vdb/vulns/149488",
    "https://github.com/advisories/GHSA-43c9-ch4w-3vh5"
  ],
  "repository_advisory_url": null,
  "severity": "medium",
  "source_code_location": "",
  "summary": "A vulnerability was detected in October CMS up to 4.3.4. This affects the function...",
  "type": "unreviewed",
  "updated_at": "2026-09-28T09:30:33Z",
  "url": "https://api.github.com/advisories/GHSA-43c9-ch4w-3vh5",
  "vulnerabilities": [],
  "withdrawn_at": null
}
cweCWE-918
receipt
Source
GitHub advisories
Its words
CWE-918
Read by
field:cwes[].cwe_id
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-06 13:46 UTC
Original
open at the source
What the source handed over
{
  "credits": [],
  "cve_id": "CVE-2026-101005",
  "cvss": {
    "score": 7.3,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 7.3,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
    },
    "cvss_v4": {
      "score": 5.5,
      "vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-918",
      "name": "Server-Side Request Forgery (SSRF)"
    }
  ],
  "description": "A vulnerability was detected in October CMS up to 4.3.4. This affects the function validateExternalImageHost of the file System/Classes/ResizeImages.php of the component SSRF Protection. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit is now public and may be used. Upgrading to version 4.3.5 is able to mitigate this issue. You should upgrade the affected component.",
  "epss": {
    "percentage": 0.00298,
    "percentile": 0.20145
  },
  "ghsa_id": "GHSA-43c9-ch4w-3vh5",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-43c9-ch4w-3vh5",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-43c9-ch4w-3vh5"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-101005"
    }
  ],
  "nvd_published_at": "2026-09-28T07:17:19Z",
  "published_at": "2026-09-28T09:30:25Z",
  "references": [
    "https://github.com/octobercms/october/security/advisories/GHSA-j2j7-7m99-6226",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-101005",
    "https://github.com/0xGenesi/CVE/blob/main/October_CMS_SSRF_IPv6_Mapped_IPv4_Bypass.md",
    "https://github.com/octobercms/october/releases/tag/v4.3.5",
    "https://vuldb.com/cve/CVE-2026-101005",
    "https://vuldb.com/submit/922294",
    "https://vuldb.com/vuln/410875",
    "https://vuldb.com/vuln/410875/cti",
    "https://www.cybersecurity-help.cz/vdb/vulns/149488",
    "https://github.com/advisories/GHSA-43c9-ch4w-3vh5"
  ],
  "repository_advisory_url": null,
  "severity": "medium",
  "source_code_location": "",
  "summary": "A vulnerability was detected in October CMS up to 4.3.4. This affects the function...",
  "type": "unreviewed",
  "updated_at": "2026-09-28T09:30:33Z",
  "url": "https://api.github.com/advisories/GHSA-43c9-ch4w-3vh5",
  "vulnerabilities": [],
  "withdrawn_at": null
}
severitymedium
receipt
Source
GitHub advisories
Its words
medium
Read by
field:severity
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-06 13:46 UTC
Original
open at the source
What the source handed over
{
  "credits": [],
  "cve_id": "CVE-2026-101005",
  "cvss": {
    "score": 7.3,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 7.3,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
    },
    "cvss_v4": {
      "score": 5.5,
      "vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-918",
      "name": "Server-Side Request Forgery (SSRF)"
    }
  ],
  "description": "A vulnerability was detected in October CMS up to 4.3.4. This affects the function validateExternalImageHost of the file System/Classes/ResizeImages.php of the component SSRF Protection. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit is now public and may be used. Upgrading to version 4.3.5 is able to mitigate this issue. You should upgrade the affected component.",
  "epss": {
    "percentage": 0.00298,
    "percentile": 0.20145
  },
  "ghsa_id": "GHSA-43c9-ch4w-3vh5",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-43c9-ch4w-3vh5",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-43c9-ch4w-3vh5"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-101005"
    }
  ],
  "nvd_published_at": "2026-09-28T07:17:19Z",
  "published_at": "2026-09-28T09:30:25Z",
  "references": [
    "https://github.com/octobercms/october/security/advisories/GHSA-j2j7-7m99-6226",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-101005",
    "https://github.com/0xGenesi/CVE/blob/main/October_CMS_SSRF_IPv6_Mapped_IPv4_Bypass.md",
    "https://github.com/octobercms/october/releases/tag/v4.3.5",
    "https://vuldb.com/cve/CVE-2026-101005",
    "https://vuldb.com/submit/922294",
    "https://vuldb.com/vuln/410875",
    "https://vuldb.com/vuln/410875/cti",
    "https://www.cybersecurity-help.cz/vdb/vulns/149488",
    "https://github.com/advisories/GHSA-43c9-ch4w-3vh5"
  ],
  "repository_advisory_url": null,
  "severity": "medium",
  "source_code_location": "",
  "summary": "A vulnerability was detected in October CMS up to 4.3.4. This affects the function...",
  "type": "unreviewed",
  "updated_at": "2026-09-28T09:30:33Z",
  "url": "https://api.github.com/advisories/GHSA-43c9-ch4w-3vh5",
  "vulnerabilities": [],
  "withdrawn_at": null
}

Text

A vulnerability was detected in October CMS up to 4.3.4. This affects the function... A vulnerability was detected in October CMS up to 4.3.4. This affects the function validateExternalImageHost of the file System/Classes/ResizeImages.php of the component SSRF Protection. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit is now public and may be used. Upgrading to version 4.3.5 is able to mitigate this issue. You should upgrade the affected component.