Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache fesod (incubating)
|
|
| Vendors & Products |
Apache fesod (incubating)
|
Mon, 01 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 01 Jun 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache fesod |
|
| CPEs | cpe:2.3:a:apache:fesod:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apache
Apache fesod |
Mon, 01 Jun 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 01 Jun 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Server-Side Request Forgery (SSRF) in the UrlImageConverter component of Apache Fesod (Incubating) fesod-sheet before 2.0.2-incubating allows attackers to cause outbound network requests to internal or otherwise restricted resources via a user-supplied image URL. Users are recommended to upgrade to version 2.0.2-incubating, which fixes this issue. | |
| Title | Apache Fesod (Incubating): Improper validation of user-supplied URLs leading to SSRF | |
| Weaknesses | CWE-918 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-06-01T14:13:17.227Z
Reserved: 2026-05-29T09:40:58.862Z
Link: CVE-2026-49328
Updated: 2026-06-01T14:13:17.227Z
Status : Modified
Published: 2026-06-01T11:16:25.803
Modified: 2026-06-01T15:16:38.830
Link: CVE-2026-49328
No data.
OpenCVE Enrichment
Updated: 2026-06-02T20:54:42Z