PatchSiren

indico CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM indico CVE published 2026-10-08

CVE-2026-107394

CVE-2026-107394 is an incomplete Server-Side Request Forgery (SSRF) check vulnerability in Indico, an event management system. The issue allows an event organizer to submit a crafted URL that points to a prohibited local target, which is accepted as valid by Indico, potentially allowing the organizer to read data returned by the target through affected Indico features. This issue is fixed in version 3.3.13.