github.com
https://github.com/aimeos/pagible CVE-2026-49262
LOW
Aimeos Pagible CMS vulnerable to Server Side Request Forgery (SSRF) via DNS rebinding in admin proxy
Record summary
CVE-2026-49262 has a selected CVSS score of 3.0 (low).
Description
In the Aimeos Pagible content management system prior to version 0.10.4, the administrative proxy route (`cmsproxy`) is vulnerable to a Server-Side Request Forgery (SSRF) attack via DNS Rebinding. A Time-of-Check to Time-of-Use (TOCTOU) race condition exists between the URL validation phase and the actual HTTP request phase, allowing attackers to access internal network resources and cloud metadata endpoints. Version 0.10.4 fixes the issue.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 12, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
pagibleBrowse aimeos / pagible | CVE List | < 0.10.4 | affected |
aimeos/pagibleBrowse Packagist / aimeos/pagible | GitHub Advisory | Before 0.10.4 · Fixed in 0.10.4 | affected |
References
3github.com
https://github.com/aimeos/pagible/commit/09a8205d513ec89ed22cdd7bdae0f4c181cee082 github.comConfirmation
https://github.com/aimeos/pagible/security/advisories/GHSA-mmj8-wcvw-6789