Skip to content

Menu
  • Home
Menu

CVE-2026-77348 – Wallos incomplete fix for CVE-2026-33407: unauthenticated httpoxy SSRF still reachable via `endpoints/payments/search.php`

Posted on September 1, 2026
CVE ID :CVE-2026-77348

Published : Aug. 31, 2026, 10:17 p.m. | 2 hours, 19 minutes ago

Description :Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, the fix for CVE-2026-33407 (GHSA-hhjq-82f8-m6rc, “SSRF via HTTP Proxy Environment Variable”) hardened endpoints/logos/search.php by disabling cURL proxying (CURLOPT_PROXY = ” + CURLOPT_NOPROXY = ‘*’). However, Wallos ships a second, near-identical, unauthenticated logo-image search endpoint — endpoints/payments/search.php — that was not given the same hardening. It still passes the HTTP_PROXY/HTTPS_PROXY environment variable straight into CURLOPT_PROXY. This issue has been patched in version 5.0.0.

Severity: 8.2 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

Post Views: 2

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme