CVE-2026-22247
MEDIUMGlpi < 11.0.5 - SSRF
Title source: ruleDescription
GLPI is a free asset and IT management software package. From version 11.0.0 to before 11.0.5, a GLPI administrator can perform SSRF request through the Webhook feature. This issue has been patched in version 11.0.5.
Scores
CVSS v3
4.1
EPSS
0.0005
EPSS Percentile
14.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
Classification
CWE
CWE-918
Status
published
Affected Products (1)
glpi-project/glpi
< 11.0.5
Timeline
Published
Feb 04, 2026
Tracked Since
Feb 18, 2026