HarborGuard / CVE
Back to search
HIGHCVE-2026-33407Published Modified CNA GitHub_M

CVE-2026-33407: Wallos: SSRF via HTTP Proxy Environment Variable

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, Wallos endpoints/logos/search.php accepts HTTP_PROXY and HTTPS_PROXY environment variables without validation, enabling SSRF via proxy hijacking. The server performs DNS resolution on user-supplied search terms, which can be controlled by attackers to trigger outbound requests to arbitrary domains. This issue has been patched in version 4.7.0.

Metrics

CVSS v4.0
8.3
Severity
HIGH
Fixed in
Affected Products
1
Affected packages
  • ellite / Wallos
    < 4.7.0
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N