Vulnerability Description
LinkAce is a self-hosted archive to collect website links. Versions prior to 2.5.3 block direct requests to private IP literals, but still performs server-side requests to internal-only resources when those resources are referenced through an internal hostname. This allows an authenticated user to trigger server-side requests to internal services reachable by the LinkAce server but not directly reachable by an external user. Version 2.5.3 patches the issue.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linkace | Linkace | < 2.5.3 |
Related Weaknesses (CWE)
References
- https://github.com/Kovah/LinkAce/security/advisories/GHSA-wp4g-qw9j-wfjgExploitVendor Advisory
FAQ
What is CVE-2026-33953?
CVE-2026-33953 is a vulnerability with a CVSS score of 8.5 (HIGH). LinkAce is a self-hosted archive to collect website links. Versions prior to 2.5.3 block direct requests to private IP literals, but still performs server-side requests to internal-only resources when...
How severe is CVE-2026-33953?
CVE-2026-33953 has been rated HIGH with a CVSS base score of 8.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-33953?
Check the references section above for vendor advisories and patch information. Affected products include: Linkace Linkace.