๐Ÿ” CVE Alert

CVE-2026-33953

HIGH 8.5

LinkAce's SSRF protection can be bypassed via internal hostname resolution in LinkAce

CVSS Score
8.5
EPSS Score
0.0%
EPSS Percentile
8th

LinkAce is a self-hosted archive to collect website links. Versions prior to 2.5.3 block direct requests to private IP literals, but still performs server-side requests to internal-only resources when those resources are referenced through an internal hostname. This allows an authenticated user to trigger server-side requests to internal services reachable by the LinkAce server but not directly reachable by an external user. Version 2.5.3 patches the issue.

CWE CWE-918
Vendor kovah
Product linkace
Published Mar 27, 2026
Last Updated Mar 30, 2026
Stay Ahead of the Next One

Get instant alerts for kovah linkace

Be the first to know when new high vulnerabilities affecting kovah linkace are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
Low
Availability
None

Affected Versions

Kovah / LinkAce
< 2.5.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Kovah/LinkAce/security/advisories/GHSA-wp4g-qw9j-wfjg