Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-18736— Shlink Server-Side Request Forgery via Short URL Title Auto-Resolution

CVSS 5.0 · Medium
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-18736

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Shlink Server-Side Request Forgery via Short URL Title Auto-Resolution
Source: CVE Program / CVE List V5
Vulnerability Description
Shlink contains a server-side request forgery vulnerability that allows authenticated API key holders to cause the server to issue arbitrary HTTP GET requests by supplying a crafted long URL during short URL creation with title auto-resolution enabled. Attackers can submit URLs pointing to public hosts that redirect to internal targets, including loopback addresses, link-local ranges, and cloud metadata endpoints such as 169.254.169.254, to exfiltrate internal service information via the HTML title element returned in the short URL creation response.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
服务端请求伪造(SSRF)
Source: CVE Program / CVE List V5

Affected Products

VendorProductAffected VersionsCPESubscribe
shlinkioShlink 2.6.0 ~ 5.1.5 -

II. Public POCs for CVE-2026-18736

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-18736

登录查看更多情报信息。

Vendor Advisories for CVE-2026-18736 (1)

Other References for CVE-2026-18736 (2)

Same Patch Batch · shlinkio · 2026-08-03 · 3 CVEs total

CVE-2026-187376.5 MEDIUMShlink Blind SQL Injection via tags/stats orderBy Parameter
CVE-2026-187384.7 MEDIUMShlink CSV Formula Injection via Visit Export CLI

IV. Related Vulnerabilities

V. Comments for CVE-2026-18736

No comments yet


Leave a comment