CVE-2026-22247
CRITICAL WAF: Medium
CVSS 9.1
Published: 2026-02-04
CWE-918
GLPI is a free asset and IT management software package. From version 11.0.0 to before 11.0.5, a GLPI administrator can perform SSRF request through the Webhook feature. This issue has been patched in version 11.0.5.
WAF Coverage Analysis
Server-Side Request Forgery (SSRF)
Medium WAF Coverage
OWASP: A10:2021 SSRF
934xxx - Node.js / Generic Injection
Affected Software
| Vendor | Product | Version |
|---|---|---|
| glpi-project | glpi | 11.0.0 - 11.0.5 |
References
- github.com (Product, Release Notes)
- github.com (Vendor Advisory)