CVE-2026-18736
Last modified
CVE-2026-18736 is a medium-severity vulnerability rated 5/10 on the CVSS scale. Shlink contains a server-side request forgery vulnerability that allows authenticated API key holders to cause the server to issue arbitrary HTTP GET requests by supplying a crafted long URL during short URL creation with title auto-resolution enabled. Attackers can submit URLs pointing to public hosts that redirect to internal targets, including loopback addresses, link-local ranges, and cloud metadata endpoints such as 169.254.169.254, to exfiltrate internal service information via the HTML title element returned in the short URL creation response.. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
Shlink contains a server-side request forgery vulnerability that allows authenticated API key holders to cause the server to issue arbitrary HTTP GET requests by supplying a crafted long URL during short URL creation with title auto-resolution enabled. Attackers can submit URLs pointing to public hosts that redirect to internal targets, including loopback addresses, link-local ranges, and cloud metadata endpoints such as 169.254.169.254, to exfiltrate internal service information via the HTML title element returned in the short URL creation response.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| shlinkio | Shlink | >= 2.6.0, <= 5.1.5 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-18736?
How severe is CVE-2026-18736?
How do I fix CVE-2026-18736?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-18726A flaw was found in open-iscsi. This vulnerability allows a …6.5
- CVE-2026-18727A flaw was found in open-iscsi's iscsiuio component. This vu…6.5
- CVE-2026-18728A flaw was found in open-iscsi. An integer underflow vulnera…6.5
- CVE-2026-18729IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote a…8.8
- CVE-2026-18730A server-side request forgery (SSRF) vulnerability was ident…7.4
- CVE-2026-18733A prompt injection vulnerability in the shell tool in Amazon…8.8
- CVE-2026-18737Shlink contains a blind SQL injection vulnerability that all…6.5
- CVE-2026-18738Shlink versions 5.0.0 through 5.1.5 contain a CSV formula in…4.7
- CVE-2026-18739A flaw was found in popt, a command-line option parsing libr…2.5
- CVE-2026-1874Always-Incorrect Control Flow Implementation vulnerability i…7.5
- CVE-2026-18741Worksuite SaaS versions prior to 6.0.14 contains a stored cr…4.8
- CVE-2026-18743A flaw was found in popt. This vulnerability allows an attac…2.5
Are you affected by CVE-2026-18736?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
