Vulnerability Description
Plunk is an open-source email platform built on top of AWS SES. Prior to 0.7.0, a Server-Side Request Forgery (SSRF) vulnerability existed in the SNS webhook handler. An unauthenticated attacker could send a crafted request that caused the server to make an arbitrary outbound HTTP GET request to any host accessible from the server. This vulnerability is fixed in 0.7.0.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Useplunk | Plunk | < 0.7.0 |
Related Weaknesses (CWE)
References
- https://github.com/useplunk/plunk/commit/b8f1ad9ab53c78f8ef063fdc125f397c8bfc765Patch
- https://github.com/useplunk/plunk/security/advisories/GHSA-xpqg-p8mp-7g44Vendor Advisory
FAQ
What is CVE-2026-32096?
CVE-2026-32096 is a vulnerability with a CVSS score of 9.3 (CRITICAL). Plunk is an open-source email platform built on top of AWS SES. Prior to 0.7.0, a Server-Side Request Forgery (SSRF) vulnerability existed in the SNS webhook handler. An unauthenticated attacker could...
How severe is CVE-2026-32096?
CVE-2026-32096 has been rated CRITICAL with a CVSS base score of 9.3/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-32096?
Check the references section above for vendor advisories and patch information. Affected products include: Useplunk Plunk.