{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/octobercms--4.1.19--4.2.25--4.3.4/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:octobercms:octobercms:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-100909"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["OctoberCMS (\u003c= 4.1.19, \u003c= 4.2.25, \u003c= 4.3.4)","October CMS (\u003c= 4.3.4)"],"_cs_severities":["high"],"_cs_tags":["web-application","ssrf"],"_cs_type":"advisory","_cs_vendors":["OctoberCMS","October CMS"],"content_html":"\u003cp\u003eOctoberCMS versions up to 4.1.19, 4.2.25, and 4.3.4 contain a server-side request forgery (SSRF) vulnerability. The flaw exists within the getSourcePathForResize function located in modules/system/classes/ResizeImages.php. An attacker can supply a malicious value to the realSourcePath argument, which is processed by the application without sufficient validation, leading to SSRF. This vulnerability allows remote, unauthenticated actors to force the OctoberCMS server to initiate arbitrary HTTP requests to internal or external resources. Given the availability of public exploit information, this represents a significant risk for organizations hosting OctoberCMS instances. Defenders should immediately prioritize patching to version 4.3.5 or 4.4.0, which includes the necessary fix (patch ID 0e9736aa2c6d6bd3d60ff6ef9e0b4d32ce387f58) to restrict path access.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to bypass firewalls and access internal services reachable from the OctoberCMS host, potentially leading to unauthorized information disclosure or interaction with internal APIs. The vulnerability affects all users of the specified vulnerable versions, exposing the web infrastructure to unauthorized server-side requests.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch OctoberCMS instances to version 4.3.5 or 4.4.0 immediately to apply the patch identified by 0e9736aa2c6d6bd3d60ff6ef9e0b4d32ce387f58.\u003c/li\u003e\n\u003cli\u003eMonitor webserver access logs for POST requests to resize functionality endpoints containing suspicious file paths or internal IP addresses in query parameters.\u003c/li\u003e\n\u003cli\u003eImplement strict egress filtering on the web server to block outbound connections to internal network segments (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) and sensitive cloud metadata endpoints (169.254.169.254).\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-28T08:49:28Z","date_published":"2026-09-28T06:47:15Z","id":"https://feed.craftedsignal.io/briefs/2026-09-octobercms-ssrf/","summary":"An unauthenticated server-side request forgery (SSRF) vulnerability in OctoberCMS allows remote attackers to manipulate the realSourcePath argument to perform unauthorized internal network requests.","title":"Server-Side Request Forgery in OctoberCMS","url":"https://feed.craftedsignal.io/briefs/2026-09-octobercms-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - OctoberCMS (\u003c= 4.1.19, \u003c= 4.2.25, \u003c= 4.3.4)","version":"https://jsonfeed.org/version/1.1"}