VDB
CRITICAL 9.1

GHSA-p85r-x2wj-mxqj

shlink has a Server-Side Request Forgery issue

Details

A Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of shlink v5.0.1 allows attackers to scan internal resources via supplying a crafted longUrl.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist / shlinkio/shlink
Introduced in: 0

No fixed version published yet for shlinkio/shlink (composer). Pin to a known-safe version or switch to an alternative.

References