Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the incomplete SSRF fix in Wallos validates webhook URLs via gethostbyname() but passes the original hostname to cURL without CURLOPT_RESOLVE pinning on 10 of 11 outbound HTTP endpoints, leaving a DNS rebinding TOCTOU window. At time of publication, there are no publicly available patches.
Metrics
Affected Vendors & Products
References
History
Thu, 07 May 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ellite
Ellite wallos |
|
| Vendors & Products |
Ellite
Ellite wallos |
Thu, 07 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 07 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the incomplete SSRF fix in Wallos validates webhook URLs via gethostbyname() but passes the original hostname to cURL without CURLOPT_RESOLVE pinning on 10 of 11 outbound HTTP endpoints, leaving a DNS rebinding TOCTOU window. At time of publication, there are no publicly available patches. | |
| Title | Incomplete fix for CVE-2026-33399: SSRF in Wallos | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-07T14:57:10.026Z
Reserved: 2026-04-22T03:53:24.407Z
Link: CVE-2026-41688
Updated: 2026-05-07T14:55:41.489Z
Status : Deferred
Published: 2026-05-07T15:16:09.253
Modified: 2026-05-07T15:45:05.947
Link: CVE-2026-41688
No data.
OpenCVE Enrichment
Updated: 2026-05-07T15:30:05Z