MEDIUM
mealie-recipes
CVE published 2026-08-05
CVE-2026-71210
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T08:16:43.240Z and has not been modified since then. Mealie's AsyncSafeTransport SSRF guard resolves a target hostname once, checks the resolved IP against private-range rules, but then issues the actual outbound HTTP request using the original hostname, which the underlying async transport re-res [truncated]