GHSA-p85r-x2wj-mxqjCriticalCVSS 9.1

shlink has a Server-Side Request Forgery issue

Published
June 15, 2026
Last Modified
August 27, 2026

🔗 CVE IDs covered (1)

📋 Description

A Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of shlink v5.0.1 allows attackers to scan internal resources via supplying a crafted longUrl.

🎯 Affected products1

  • composer/shlinkio/shlink:<= 5.0.1

🔗 References (3)