Home

Description

Server-Side Request Forgery (SSRF) in the UrlImageConverter component of Apache Fesod (Incubating) fesod-sheet before 2.0.2-incubating allows attackers to cause outbound network requests to internal or otherwise restricted resources via a user-supplied image URL. Users are recommended to upgrade to version 2.0.2-incubating, which fixes this issue.

PUBLISHED Reserved 2026-05-29 | Published 2026-06-01 | Updated 2026-06-01 | Assigner apache

Problem types

CWE-918 Server-Side Request Forgery (SSRF)

Product status

Default status
unaffected

Any version before 2.0.2-incubating
affected

Credits

Xu Han finder

References

github.com/apache/fesod/pull/917 patch

github.com/apache/fesod/releases/tag/2.0.2-incubating release-notes

fesod.apache.org/docs/download

lists.apache.org/thread/c1pb5b66h02p9tlrnfbwcgcz85v16fkj vendor-advisory

cve.org (CVE-2026-49328)

nvd.nist.gov (CVE-2026-49328)

Download JSON