Home

Description

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, the patch introduced in commit e8a513591 (CVE-2026-30840) added SSRF protection to notification test endpoints but left three additional attack surfaces unprotected: the AI Ollama host parameter, the AI recommendations endpoint, and the notification cron job. An authenticated user can reach internal network services, cloud metadata endpoints (AWS IMDSv1, GCP, Azure IMDS), or localhost-bound services by supplying a crafted URL to any of these endpoints. This issue has been patched in version 4.7.0.

PUBLISHED Reserved 2026-03-19 | Published 2026-03-24 | Updated 2026-03-24 | Assigner GitHub_M




HIGH: 7.1CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-918: Server-Side Request Forgery (SSRF)

Product status

< 4.7.0
affected

References

github.com/...Wallos/security/advisories/GHSA-r82v-p8cg-rgx3

github.com/...ommit/e87387f0ebb540cd33e6dfda7181db9db650ecef

github.com/ellite/Wallos/commit/e8a513591

cve.org (CVE-2026-33401)

nvd.nist.gov (CVE-2026-33401)

Download JSON