CVE-2026-18738 is a CSV formula injection vulnerability in Shlink versions 5.0.0 through 5.1.5. An unauthenticated remote attacker can plant spreadsheet formulas into exported visit data by supplying malicious values in User-Agent, Referer, or request path headers. When an administrator opens the exported CSV file in a spreadsheet application, the formulas are executed.
CVE-2026-18736 is a server-side request forgery vulnerability in Shlink that allows authenticated API key holders to cause the server to issue arbitrary HTTP GET requests. This can lead to the exfiltration of internal service information via the HTML title element returned in the short URL creation response. The vulnerability is particularly concerning because attackers can submit URLs pointing to public [truncated]