CVE-2026-27127

MEDIUM

Craft CMS 4.5.0-RC1-4.16.18/5.0.0-RC1-5.8.22 - SSRF

Title source: llm
STIX 2.1

Description

Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, the SSRF validation in Craft CMS’s GraphQL Asset mutation performs DNS resolution separately from the HTTP request. This Time-of-Check-Time-of-Use (TOCTOU) vulnerability enables DNS rebinding attacks, where an attacker’s DNS server returns different IP addresses for validation compared to the actual request. This is a bypass of the security fix for CVE-2025-68437 that allows access to all blocked IPs, not just IPv6 endpoints. Exploitation requires GraphQL schema permissions for editing assets in the `<VolumeName>` volume and creating assets in the `<VolumeName>` volume. These permissions may be granted to authenticated users with appropriate GraphQL schema access and/or Public Schema (if misconfigured with write permissions). Versions 4.16.19 and 5.8.23 patch the issue.

Scores

CVSS v3 6.3
EPSS 0.0001
EPSS Percentile 0.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-367
Status published
Products (4)
craftcms/cms 5.0.0-RC1 - 5.8.23Packagist
craftcms/craft_cms 3.5.0
craftcms/craft_cms 5.0.0 (2 CPE variants)
craftcms/craft_cms 3.5.1 - 4.16.19
Published Feb 24, 2026
Tracked Since Feb 24, 2026