๐Ÿ” CVE Alert

CVE-2026-33659

LOW 3.5

EspoCRM: SSRF via DNS Rebinding in Attachment fromImageUrl Endpoint Allows Internal Network Access

CVSS Score
3.5
EPSS Score
0.0%
EPSS Percentile
12th

EspoCRM is an open source customer relationship management application. In versions 9.3.3 and below, the POST /api/v1/Attachment/fromImageUrl endpoint is vulnerable to Server-Side Request Forgery (SSRF) via a DNS rebinding (TOCTOU) condition. Host validation uses dns_get_record() but the actual HTTP request resolves hostnames through curl's internal resolver (gethostbyname()), allowing the two lookups to return different IP addresses for the same hostname. A secondary issue exists where an empty DNS result (due to DNS failure, IPv6-only domains, or non-existent hostnames) causes the validation to implicitly allow the host without further checks. An authenticated attacker with default attachment creation access can exploit this gap to bypass internal IP restrictions and scan internal network ports, confirm the existence of internal hosts, and interact with internal HTTP-based services, though data extraction from binary protocol services and remote code execution are not possible through this endpoint. This issue has been fixed in version 9.3.4.

CWE CWE-918 CWE-367
Vendor espocrm
Product espocrm
Published Apr 13, 2026
Last Updated Apr 14, 2026
Stay Ahead of the Next One

Get instant alerts for espocrm espocrm

Be the first to know when new low vulnerabilities affecting espocrm espocrm are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

espocrm / espocrm
< 9.3.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/espocrm/espocrm/security/advisories/GHSA-6m4j-fwrx-crh7 github.com: https://github.com/espocrm/espocrm/commit/dca03cc3458e487362c26c746378a2d4de9990b1 github.com: https://github.com/espocrm/espocrm/releases/tag/9.3.4