Description
Mealie 3.26.0 through 3.28.0 contains a server-side request forgery vulnerability in the OpenID Connect avatar fetch that ignores ports when allowlisting the identity provider hostname. Authenticated OIDC users who control their picture URL can make the server send GET requests to arbitrary ports on the provider's internal address on each login.
Published: 2026-10-10
Score: 2.3 Low
EPSS: n/a
KEV: No
Impact: Server‑Side Request Forgery (SSRF)
Action: Patch Now
AI Analysis

Impact

The flaw in Mealie’s OpenID Connect avatar fetch allows an authenticated user to set a picture URL that is used during login. The service ignores the port when allow‑listing the provider hostname, enabling the attacker to instruct the server to issue GET requests to arbitrary ports on the provider’s internal address. This can leak internal network information or access services that are only reachable from within the internal network, compromising confidentiality and potentially permitting lateral movement. The vulnerability is limited to SSRF and does not provide direct code execution or privilege escalation on its own, but it can be a stepping stone to more severe attacks if the internal services are sensitive.

Affected Systems

Mealie, the recipe‑management application provided by mealie‑recipes, is affected in releases 3.26.0 through 3.28.0. Any installation running one of these versions with OIDC authentication enabled is vulnerable.

Risk and Exploitability

The CVSS score of 2.3 reflects a low severity impact when considered in isolation. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no confirmed exploit evidence in the wild yet. However, because the attacker only needs a legitimate OIDC account to manipulate the picture URL, the threat is realistic in environments where such accounts exist. The attacker can trigger the vulnerable request on each login, making the attack repeatable over time. Although the risk appears limited, the potential to probe internal services should not be ignored.

Generated by OpenCVE AI on October 10, 2026 at 19:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Mealie to a version that fixes the SSRF issue, removing the allow‑list bug in the OIDC avatar fetch.
  • If an immediate upgrade is not possible, configure the application to reject or sanitize custom picture URLs, ensuring only HTTPS URLs pointing to trusted domains are accepted. This limits the ability of an attacker to supply arbitrary URLs.
  • Apply network segmentation or firewall rules to block outbound traffic from the web‑server to internal network ports that are not essential for normal operation, preventing the SSRF from reaching sensitive services.

Generated by OpenCVE AI on October 10, 2026 at 19:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Description Mealie 3.26.0 through 3.28.0 contains a server-side request forgery vulnerability in the OpenID Connect avatar fetch that ignores ports when allowlisting the identity provider hostname. Authenticated OIDC users who control their picture URL can make the server send GET requests to arbitrary ports on the provider's internal address on each login.
Title Mealie 3.26.0 through 3.28.0 SSRF via OIDC Picture Claim Avatar Fetch
First Time appeared Mealie
Mealie mealie
Weaknesses CWE-918
CPEs cpe:2.3:a:mealie:mealie:*:*:*:*:*:*:*:*
Vendors & Products Mealie
Mealie mealie
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-10T18:16:57.811Z

Reserved: 2026-10-10T18:08:12.108Z

Link: CVE-2026-108594

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-10T19:16:57.770

Modified: 2026-10-10T19:16:57.880

Link: CVE-2026-108594

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T19:30:17Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)