| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-pf9c-ch8r-2958 | Statamic CMS: Server-Side Request Forgery via Glide |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 29 May 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Statamic
Statamic cms |
|
| Vendors & Products |
Statamic
Statamic cms |
Fri, 29 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.22 and 6.18.1, the Glide image proxy's URL validation could be bypassed using an IP representation that wasn't normalized before the public-IP check. An unauthenticated user could cause the server to make HTTP requests to internal addresses — including loopback, private network, and cloud metadata endpoints. This affects sites that pass user-supplied URLs to Glide. Sites running PHP 8.3 or newer are not affected. This vulnerability is fixed in 5.73.22 and 6.18.1. | |
| Title | Statamic: Server-Side Request Forgery via Glide | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-29T19:36:42.883Z
Reserved: 2026-05-12T21:59:25.665Z
Link: CVE-2026-45660
Updated: 2026-05-29T19:36:36.536Z
Status : Received
Published: 2026-05-29T18:17:11.640
Modified: 2026-05-29T18:17:11.640
Link: CVE-2026-45660
No data.
OpenCVE Enrichment
Updated: 2026-05-29T20:00:05Z
Github GHSA