MEDIUM
indico
CVE published 2026-10-08
CVE-2026-107394
CVE-2026-107394 is an incomplete Server-Side Request Forgery (SSRF) check vulnerability in Indico, an event management system. The issue allows an event organizer to submit a crafted URL that points to a prohibited local target, which is accepted as valid by Indico, potentially allowing the organizer to read data returned by the target through affected Indico features. This issue is fixed in version 3.3.13.