Home

Description

Koha versions up to 25.11 contain a Server-Side Request Forgery (SSRF) vulnerability via the Z39.50/SRU server configuration. This allows authenticated attackers to perform internal network scanning and identify running services by analyzing server response times.

PUBLISHED Reserved 2026-02-16 | Published 2026-06-03 | Updated 2026-06-04 | Assigner mitre

References

g03m0n.github.io/posts/cve-2026-26379/ exploit

github.com/Koha-Community/Koha

g03m0n.github.io/

g03m0n.github.io/posts/cve-2026-26379/

cve.org (CVE-2026-26379)

nvd.nist.gov (CVE-2026-26379)

Download JSON