HarborGuard / CVE
Back to search
CRITICALCVE-2026-32096Published Modified CNA GitHub_M

CVE-2026-32096: Plunk has SSRF via unvalidated AWS SNS SubscriptionConfirmation in POST /webhooks/sns

Plunk is an open-source email platform built on top of AWS SES. Prior to 0.7.0, a Server-Side Request Forgery (SSRF) vulnerability existed in the SNS webhook handler. An unauthenticated attacker could send a crafted request that caused the server to make an arbitrary outbound HTTP GET request to any host accessible from the server. This vulnerability is fixed in 0.7.0.

Metrics

CVSS v3.1
9.3
Severity
CRITICAL
Fixed in
Affected Products
1
Affected packages
  • useplunk / plunk
    < 0.7.0
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N