CVE-2026-25493

MEDIUM WAF: Medium
CVSS 6.5 Published: 2026-02-09
CWE-918

Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the saveAsset GraphQL mutation validates the initial URL hostname and resolved IP against a blocklist, but Guzzle follows HTTP redirects by default. An attacker can bypass all SSRF protections by hosting a redirect that points to cloud metadata endpoints or any internal IP addresses. This issue is patched in versions 4.16.18 and 5.8.22.

WAF Coverage Analysis

Server-Side Request Forgery (SSRF) Medium WAF Coverage

OWASP: A10:2021 SSRF

934xxx - Node.js / Generic Injection

Affected Software

VendorProductVersion
craftcmscraft_cmsup to 4.16.18
craftcmscraft_cmsup to 5.8.22
craftcmscraft_cms4.0.0
craftcmscraft_cms4.0.0
craftcmscraft_cms4.0.0
craftcmscraft_cms4.0.0
craftcmscraft_cms5.0.0
craftcmscraft_cms5.0.0

References

Back to CVE Database