PatchSiren

ridafkih CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW ridafkih CVE published 2026-08-19

CVE-2026-75583

CVE-2026-75583 is a server-side request forgery (SSRF) guard bypass vulnerability in keeper.sh's calendar module version prior to 2.18.14. Authenticated attackers can exploit a DNS rebinding attack to reach private network addresses. The SSRF guard validates a hostname's resolved IP addresses but discards them before the actual HTTP connection is opened, allowing an attacker to return a public address dur [truncated]