Vulnerability Description
Koha versions up to 25.11 contain a Server-Side Request Forgery (SSRF) vulnerability via the Z39.50/SRU server configuration. This allows authenticated attackers to perform internal network scanning and identify running services by analyzing server response times.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Koha | Koha | <= 25.11.00 |
Related Weaknesses (CWE)
References
- https://g03m0n.github.io/Third Party Advisory
- https://g03m0n.github.io/posts/cve-2026-26379/ExploitThird Party Advisory
- https://github.com/Koha-Community/KohaProduct
- https://g03m0n.github.io/posts/cve-2026-26379/ExploitThird Party Advisory
FAQ
What is CVE-2026-26379?
CVE-2026-26379 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Koha versions up to 25.11 contain a Server-Side Request Forgery (SSRF) vulnerability via the Z39.50/SRU server configuration. This allows authenticated attackers to perform internal network scanning a...
How severe is CVE-2026-26379?
CVE-2026-26379 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-26379?
Check the references section above for vendor advisories and patch information. Affected products include: Koha Koha.