NONE · 0

CVE-2026-61640

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, Admin-configured OIDC token_url and user_info_url in includes/oidc/handle_oidc_callback.php:18-49 are use...

Vulnerability Description

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, Admin-configured OIDC token_url and user_info_url in includes/oidc/handle_oidc_callback.php:18-49 are used directly in curl_init() with zero SSRF filtering. Unlike logo/webhook URLs which have validate_webhook_url_for_ssrf(), OIDC URLs bypass all protections. Admin sets URL to http://169.254.169.254/latest/meta-data/ for cloud metadata access or internal network pivoting. This issue has been patched in version 4.9.6.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-61640?

CVE-2026-61640 is a documented vulnerability. Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, Admin-configured OIDC token_url and user_info_url in includes/oidc/handle_oidc_callback.php:18-49 are use...

How severe is CVE-2026-61640?

CVSS scoring is not yet available for CVE-2026-61640. Check NVD for updates.

Is there a patch for CVE-2026-61640?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.