LOW
Contao
CVE published 2026-07-31
CVE-2026-57232
The Contao Feed Reader front-end module is vulnerable to SSRF attacks due to a lack of scheme or private-address validation. A backend user with module-edit permissions can make the server request internal network services, loopback addresses, or cloud metadata endpoints. This issue affects Contao versions from 5.3.35 through 5.3.47 and from 5.7.0-RC1 through 5.7.8. The vulnerability is fixed in Contao ve [truncated]