A AegiFlow
CRITICALCVSS 9.1EPSS 0.3%

CVE-2026-50887

shlink has a Server-Side Request Forgery issue

Published
2026-06-15
Modified
2026-08-27
EPSS percentile
21%
Aliases
GHSA-p85r-x2wj-mxqj
Sources
github-advisory

Summary

A Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of shlink v5.0.1 allows attackers to scan internal resources via supplying a crafted longUrl.

Affected packages

EcosystemPackageAffected versionsFixed versions
Packagistshlinkio/shlink

Remediation: No patched version is listed by GitHub.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.