CVE-2026-46556
MEDIUMFlaskBB: SSRF in get_image_info() via unrestricted avatar URL
Title source: cnaDescription
FlaskBB is a Forum Software written in Python using the micro framework Flask. Prior to version 2.2.1, a Server-Side Request Forgery (SSRF) vulnerability in get_image_info() allows any authenticated user to force the server to send HTTP requests to arbitrary internal endpoints, including cloud metadata services. This is a blind SSRF with confirmed internal port scanning and internal API triggering capabilities. Version 2.2.1 patches the issue.
References (2)
Core 2
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/flaskbb/flaskbb/security/advisories/GHSA-xq32-9g7q-7297
X_Refsource_Misc x_refsource_misc
https://github.com/flaskbb/flaskbb/commit/e87e585f54bbe36694e91d52ee9b2d2e65dd4ab5
Scores
CVSS v3
6.5
EPSS
0.0021
EPSS Percentile
11.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-918
Status
published
Products (1)
flaskbb/flaskbb
< 2.2.1
Published
Jul 21, 2026
Tracked Since
Jul 22, 2026