Idno is a social publishing platform. Prior to version 1.6.4, a logic error in the API authentication flow causes the CSRF protection on the URL unfurl service endpoint to be trivially bypassed by any unauthenticated remote attacker. Combined with the absence of a login requirement on the endpoint itself, this allows an attacker to force the server to make arbitrary outbound HTTP requests to any host, including internal network addresses and cloud instance metadata services, and retrieve the response content. This issue has been patched in version 1.6.4.
History

Fri, 06 Mar 2026 04:45:00 +0000

Type Values Removed Values Added
Description Idno is a social publishing platform. Prior to version 1.6.4, a logic error in the API authentication flow causes the CSRF protection on the URL unfurl service endpoint to be trivially bypassed by any unauthenticated remote attacker. Combined with the absence of a login requirement on the endpoint itself, this allows an attacker to force the server to make arbitrary outbound HTTP requests to any host, including internal network addresses and cloud instance metadata services, and retrieve the response content. This issue has been patched in version 1.6.4.
Title Idno: Unauthenticated SSRF via URL Unfurl Endpoint
Weaknesses CWE-918
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-03-06T04:13:19.621Z

Reserved: 2026-02-27T20:57:47.709Z

Link: CVE-2026-28508

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-06T05:16:35.233

Modified: 2026-03-06T05:16:35.233

Link: CVE-2026-28508

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.