Server-Side Request Forgery in OctoberCMS
An unauthenticated server-side request forgery (SSRF) vulnerability in OctoberCMS allows remote attackers to manipulate the realSourcePath argument to perform unauthorized internal network requests.
CVE search metadata
CVE search record: CVE-2026-100909. Severity: high. CVSS: 7.3. KEV: no. Product: OctoberCMS (<= 4.1.19, <= 4.2.25, <= 4.3.4). Brief: Server-Side Request Forgery in OctoberCMS. Brief link: https://feed.craftedsignal.io/briefs/2026-09-octobercms-ssrf/
OctoberCMS versions up to 4.1.19, 4.2.25, and 4.3.4 contain a server-side request forgery (SSRF) vulnerability. The flaw exists within the getSourcePathForResize function located in modules/system/classes/ResizeImages.php. An attacker can supply a malicious value to the realSourcePath argument, which is processed by the application without sufficient validation, leading to SSRF. This vulnerability allows remote, unauthenticated actors to force the OctoberCMS server to initiate arbitrary HTTP requests to internal or external resources. Given the availability of public exploit information, this represents a significant risk for organizations hosting OctoberCMS instances. Defenders should immediately prioritize patching to version 4.3.5 or 4.4.0, which includes the necessary fix (patch ID 0e9736aa2c6d6bd3d60ff6ef9e0b4d32ce387f58) to restrict path access.
Impact
Successful exploitation allows an attacker to bypass firewalls and access internal services reachable from the OctoberCMS host, potentially leading to unauthorized information disclosure or interaction with internal APIs. The vulnerability affects all users of the specified vulnerable versions, exposing the web infrastructure to unauthorized server-side requests.
Recommendation
- Patch OctoberCMS instances to version 4.3.5 or 4.4.0 immediately to apply the patch identified by 0e9736aa2c6d6bd3d60ff6ef9e0b4d32ce387f58.
- Monitor webserver access logs for POST requests to resize functionality endpoints containing suspicious file paths or internal IP addresses in query parameters.
- Implement strict egress filtering on the web server to block outbound connections to internal network segments (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) and sensitive cloud metadata endpoints (169.254.169.254).
Immediate actions
Upgrade OctoberCMS to 4.3.5 or 4.4.0
Mitigations
Restrict outbound server egress to internal CIDR ranges
CVE-2026-100909