CVE 5.4 MEDIUM

Statamic: Server-Side Request Forgery via Glide_CVE-2026-45660

5.4 / 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N

Description

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.22 and 6.18.1, the Glide image proxy's URL validation could be bypassed using an IP representation that wasn't normalized before the public-IP check. An unauthenticated user could cause the server to make HTTP requests to internal addresses — including loopback, private network, and cloud metadata endpoints. This affects sites that pass user-supplied URLs to Glide. Sites running PHP 8.3 or newer are not affected. This vulnerability is fixed in 5.73.22 and 6.18.1.

Basic Information

ID CVE-2026-45660
Source GitHub_M
Published May 29, 2026 at 16:43

Affected Product

Vendor statamic
Product cms
Version < 5.73.22
Affected Versions statamic cms < 5.73.22
statamic cms >= 6.0.0-alpha.1, < 6.18.1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.