Description
Feehi CMS 2.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the UEditor catchimage endpoint. The private-IP validation does not block loopback or link-local addresses, allowing an attacker to make the server probe internal HTTP services through response differences.
Published: 2026-10-05
Score: n/a
EPSS: n/a
KEV: No
Impact: Server‑Side Request Forgery
Action: Patch
AI Analysis

Impact

The vulnerability is a Server‑Side Request Forgery (SSRF) in the UEditor catchimage endpoint of Feehi CMS 2.1.1. The endpoint fetches images from remote URLs, but the private‑IP validation that should block loopback and link‑local addresses is omitted. An attacker can thus instruct the service to request internal URLs and determine whether internal HTTP services respond differently, leaking information about the internal network.

Affected Systems

Only the Feehi CMS 2.1.1 distribution contains this flaw. The vulnerability exists in the catchimage handler that retrieves images via HTTP requests. No other versions or products are documented. Administrators of installations running this specific CMS version should verify their deployment.

Risk and Exploitability

Because the flaw allows external input to trigger server‑initiated requests, the attack vector is remote, via an HTTP request to the vulnerable endpoint. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that publicly available exploits may not yet be widespread. Nevertheless, the omission of loopback and link‑local address checks creates a high‑impact condition that can lead to internal network reconnaissance or further exploitation of exposed internal services. The severity is naturally high, and mitigation should be prioritized even in the absence of published CVSS metrics.

Generated by OpenCVE AI on October 5, 2026 at 21:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Feehi CMS to the latest version that has fixed the SSRF in the catchimage endpoint.
  • If no update is immediately available, disable or remove the catchimage endpoint to stop external image fetching.
  • Block the server’s outbound connections to private IP ranges (127.0.0.0/8, 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) using firewall or network segmentation.
  • If disabling the feature is not possible, implement a reverse proxy or a strict whitelist that only allows requests to known safe external domains.
  • Audit the CMS configuration for any other endpoints that fetch external resources and apply the same private‑IP restrictions.

Generated by OpenCVE AI on October 5, 2026 at 21:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 22:00:00 +0000

Type Values Removed Values Added
Title Server‑Side Request Forgery in Feehi CMS 2.1.1 UEditor Catchimage Endpoint
Weaknesses CWE-918

Mon, 05 Oct 2026 20:15:00 +0000

Type Values Removed Values Added
Description Feehi CMS 2.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the UEditor catchimage endpoint. The private-IP validation does not block loopback or link-local addresses, allowing an attacker to make the server probe internal HTTP services through response differences.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-05T20:07:28.383Z

Reserved: 2026-09-22T00:00:00.000Z

Link: CVE-2026-95265

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T20:17:29.313

Modified: 2026-10-05T20:17:29.313

Link: CVE-2026-95265

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T21:45:20Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)