Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 31 Aug 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ellite
Ellite wallos |
|
| Vendors & Products |
Ellite
Ellite wallos |
Mon, 31 Aug 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints/notifications/testemailnotifications.php accepts smtpaddress and smtpport from POST body with zero SSRF validation. PHPMailer connects to attacker-supplied host:port. Every other notification endpoint uses ssrf_helper.php but email was missed. Any authenticated user can probe internal network, cloud metadata. This issue has been patched in version 4.9.6. | |
| Title | Wallos: SSRF via Test Email Notification - unvalidated SMTP host/port | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-31T20:41:04.513Z
Reserved: 2026-07-10T17:38:57.111Z
Link: CVE-2026-61638
No data.
Status : Received
Published: 2026-08-31T21:17:16.950
Modified: 2026-08-31T21:17:16.950
Link: CVE-2026-61638
No data.
OpenCVE Enrichment
Updated: 2026-08-31T22:00:05Z
-
CWE-918
Server-Side Request Forgery (SSRF)