Loading market data...
← Back to CVE feed

CVE-2026-82476

MEDIUM CVSS 5.3 View on NVD ↗

Description

Memos through 0.30.0 omits the 100.64.0.0/10 carrier-grade NAT address range from SSRF protection in its link-metadata fetcher, allowing unauthenticated attackers to bypass IP validation. Attackers can make the server request internal hosts in that range including cloud metadata services and read page titles and descriptions back.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Published: Aug 29, 2026 17:18 UTC Modified: Aug 29, 2026 17:18 UTC