← Retour aux CVEs
CVE-2026-33953
HIGH8.5
Description
LinkAce is a self-hosted archive to collect website links. Versions prior to 2.5.3 block direct requests to private IP literals, but still performs server-side requests to internal-only resources when those resources are referenced through an internal hostname. This allows an authenticated user to trigger server-side requests to internal services reachable by the LinkAce server but not directly reachable by an external user. Version 2.5.3 patches the issue.
Details CVE
Score CVSS v3.18.5
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisLOW
Interaction utilisateurNONE
Publie3/27/2026
Derniere modification3/31/2026
Sourcenvd
Observations honeypot0
Produits affectes
linkace:linkace
Faiblesses (CWE)
CWE-918
References
https://github.com/Kovah/LinkAce/security/advisories/GHSA-wp4g-qw9j-wfjg(security-advisories@github.com)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.