๐Ÿ” CVE Alert

CVE-2026-46556

MEDIUM 6.5

FlaskBB: SSRF in get_image_info() via unrestricted avatar URL

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

FlaskBB is a Forum Software written in Python using the micro framework Flask. Prior to version 2.2.1, a Server-Side Request Forgery (SSRF) vulnerability in get_image_info() allows any authenticated user to force the server to send HTTP requests to arbitrary internal endpoints, including cloud metadata services. This is a blind SSRF with confirmed internal port scanning and internal API triggering capabilities. Version 2.2.1 patches the issue.

CWE CWE-918
Vendor flaskbb
Product flaskbb
Published Jul 21, 2026
Stay Ahead of the Next One

Get instant alerts for flaskbb flaskbb

Be the first to know when new medium vulnerabilities affecting flaskbb flaskbb are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

flaskbb / flaskbb
< 2.2.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/flaskbb/flaskbb/security/advisories/GHSA-xq32-9g7q-7297 github.com: https://github.com/flaskbb/flaskbb/commit/e87e585f54bbe36694e91d52ee9b2d2e65dd4ab5