CVE-2026-33407

CRITICAL

Wallos: SSRF via HTTP Proxy Environment Variable

Title source: cna
STIX 2.1

Description

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, Wallos endpoints/logos/search.php accepts HTTP_PROXY and HTTPS_PROXY environment variables without validation, enabling SSRF via proxy hijacking. The server performs DNS resolution on user-supplied search terms, which can be controlled by attackers to trigger outbound requests to arbitrary domains. This issue has been patched in version 4.7.0.

Scores

CVSS v3 9.1
EPSS 0.0006
EPSS Percentile 19.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-918 CWE-922
Status published
Products (2)
ellite/Wallos < 4.7.0
wallosapp/wallos < 4.7.0
Published Mar 24, 2026
Tracked Since Mar 24, 2026