CVE-2026-34590
CVE-2026-34590 is a medium-severity vulnerability in Gitroom Postiz with a CVSS 3.x base score of 5.4. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-918.
Key facts
- Severity: Medium (CVSS 3.x base score 5.4)
- EPSS exploit prediction: 0% (14th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-18452
- Weakness: CWE-918
- Affected product: Gitroom Postiz
- Published:
- Last modified:
Description
Postiz is an AI social media scheduling tool. Prior to version 2.21.4, the POST /webhooks/ endpoint for creating webhooks uses WebhooksDto which validates the url field with only @IsUrl() (format check), missing the @IsSafeWebhookUrl validator that blocks internal/private network addresses. The update (PUT /webhooks/) and test (POST /webhooks/send) endpoints correctly apply @IsSafeWebhookUrl. When a post is published, the orchestrator fetches the stored webhook URL without runtime validation, enabling blind SSRF against internal services. This issue has been patched in version 2.21.4.
Frequently asked questions
- What is CVE-2026-34590?
- Postiz is an AI social media scheduling tool. Prior to version 2.21.4, the POST /webhooks/ endpoint for creating webhooks uses WebhooksDto which validates the url field with only @IsUrl() (format check), missing the @IsSafeWebhookUrl validator that blocks internal/private network addresses. The update (PUT /webhooks/) and test (POST /webhooks/send) endpoints correctly apply @IsSafeWebhookUrl. When a post is published, the orchestrator fetches the stored webhook URL without runtime validation, enabling blind SSRF against internal services. This issue has been patched in version 2.21.4.
- How severe is CVE-2026-34590?
- CVE-2026-34590 has a CVSS 3.x base score of 5.4, rated medium severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is low, integrity low, and availability none.
- Is CVE-2026-34590 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (14th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-34590?
- CVE-2026-34590 affects Gitroom Postiz. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-34590?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2026-34590 have an EU (EUVD) identifier?
- Yes. CVE-2026-34590 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-18452.
- When was CVE-2026-34590 published?
- CVE-2026-34590 was published on 2026-04-02 and last updated on 2026-07-24.
References
- https://github.com/gitroomhq/postiz-app/commit/5ae4c950db6aa516a31454b7a45b9480bca40a11
- https://github.com/gitroomhq/postiz-app/releases/tag/v2.21.4
- https://github.com/gitroomhq/postiz-app/security/advisories/GHSA-wc9c-7cv8-m225
Affected products (1)
- cpe:2.3:a:gitroom:postiz:*:*:*:*:*:*:*:*
More vulnerabilities in Gitroom Postiz
- CVE-2026-42298 — Critical (CVSS 10.0): Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vulnerability in the Build and…
- CVE-2026-42556 — High (CVSS 8.9): Postiz is an AI social media scheduling tool. From version 2.21.6 to before version 2.21.7, any authenticated user who…
- CVE-2026-40487 — High (CVSS 8.9): Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any…
- CVE-2026-34577 — High (CVSS 8.6): Postiz is an AI social media scheduling tool. Prior to version 2.21.3, the GET /public/stream endpoint in…
- CVE-2026-40168 — High (CVSS 8.2): Postiz is an AI social media scheduling tool. Prior to 2.21.5, the /api/public/stream endpoint is vulnerable to SSRF.…
- CVE-2026-34576 — High (CVSS 7.7): Postiz is an AI social media scheduling tool. Prior to version 2.21.3, the POST /public/v1/upload-from-url endpoint…
All CVEs affecting Gitroom Postiz →
Other CWE-918 (Server-Side Request Forgery (SSRF)) vulnerabilities
- CVE-2026-69502 — Critical (CVSS 10.0): Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a…
- CVE-2026-65801 — Critical (CVSS 10.0): Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges…
- CVE-2026-48331 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in…
- CVE-2026-54735 — Critical (CVSS 10.0): Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version…
- CVE-2026-57106 — Critical (CVSS 10.0): Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-15409 — Critical (CVSS 10.0): A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A…
Browse all CWE-918 (Server-Side Request Forgery (SSRF)) vulnerabilities →