{"id":"CVE-2026-9557","details":"A Server-Side Request Forgery (SSRF) vulnerability exists in Mautic's Focus component. Due to insufficient validation of user-supplied URLs, an authenticated user can trigger outbound HTTP requests from the hosting server, enabling internal network reconnaissance or forcing requests to arbitrary internal or external destinations.","aliases":["GHSA-jmv8-8j9j-rcpc"],"modified":"2026-08-07T11:31:07.608796037Z","published":"2026-05-29T09:38:40.857Z","database_specific":{"cna_assigner":"Mautic","cwe_ids":["CWE-918"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/9xxx/CVE-2026-9557.json","unresolved_ranges":[{"extracted_events":[{"introduced":"4.0.0"},{"fixed":"4.4.20"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://packagist.org"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/9xxx/CVE-2026-9557.json"},{"type":"ADVISORY","url":"https://github.com/mautic/mautic/security/advisories/GHSA-jmv8-8j9j-rcpc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-9557"},{"type":"PACKAGE","url":"https://github.com/mautic/mautic"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mautic/mautic","events":[{"introduced":"96b53794017cde917e1e4262ebaaae5099e3586a"},{"fixed":"03865b3dfbe0064df47d176b897bbfe1ba60e1d3"},{"introduced":"12f062e87dd1c470893724b12be7b623ecd22f2b"},{"fixed":"bd92ad789274317c82f6e1e1179d56f7406bc702"},{"introduced":"21ab270a3516635551d7464fc604f4e5e1ae3aea"},{"fixed":"789364ee4aaf8aef5e6d91642336c1f446d5521b"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"5.0.0"},{"fixed":"5.2.11"},{"introduced":"6.0.0"},{"fixed":"6.0.9"},{"introduced":"7.0.0"},{"fixed":"7.1.2"}]}}],"versions":["5.2.10","6.0.8","7.1.1","7.1.0","7.1.0-rc","6.0.7","5.2.9","7.0.0-beta","6.0.6","5.2.8","6.0.5","6.0.4","7.0.0-alpha","6.0.3","6.0.2","5.2.6","5.2.5","6.0.1","6.0.0","5.2.4","5.2.2","5.2.3","6.0.0-alpha","5.2.1","5.2.0","5.1.0","5.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-9557.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"}]}