LOW
ridafkih
CVE published 2026-08-19
CVE-2026-75583
CVE-2026-75583 is a server-side request forgery (SSRF) guard bypass vulnerability in keeper.sh's calendar module version prior to 2.18.14. Authenticated attackers can exploit a DNS rebinding attack to reach private network addresses. The SSRF guard validates a hostname's resolved IP addresses but discards them before the actual HTTP connection is opened, allowing an attacker to return a public address dur [truncated]