Home
Description
Koha versions up to 25.11 contain a Server-Side Request Forgery (SSRF) vulnerability via the Z39.50/SRU server configuration. This allows authenticated attackers to perform internal network scanning and identify running services by analyzing server response times.
References
g03m0n.github.io/posts/cve-2026-26379/
github.com/Koha-Community/Koha
g03m0n.github.io/posts/cve-2026-26379/