What is CVE-2026-57232?
A Server-Side Request Forgery (SSRF) vulnerability exists in Contao CMS's Feed Reader module. Affected versions (5.3.35-5.3.47 and 5.7.0-RC1-5.7.8) do not validate URL schemes or private addresses, allowing a backend user with module-edit permissions to make requests to internal services. Upgrade to the latest Contao version to mitigate this issue.
Azərbaycanca: Contao CMS-in Feed Reader modulunda açıqlıq aşkarlanıb. 5.3.35–5.3.47 və 5.7.0-RC1–5.7.8 versiyalarında backend istifadəçisi xüsusi hazırlanmış RSS feed URL-i daxil edərək Server-Side Request Forgery (SSRF) hücumu həyata keçirə bilər. Modulu redaktə edə bilən istifadəçiləri məhdudlaşdırmaq və ya Contao-nu ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which versions of Contao CMS are affected by the Server-Side Request Forgery (SSRF) vulnerability tracked as CVE-2026-57232?
The vulnerability affects Contao CMS versions 5.3.35 through 5.3.47 and 5.7.0-RC1 through 5.7.8.
What privileges does an attacker need to exploit the CVE-2026-57232 vulnerability?
The attacker must be a backend user with permissions to edit the Feed Reader module.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.