๐Ÿ” CVE Alert

CVE-2026-48013

MEDIUM 4.1

Shopware: SSRF in Media External-Link Endpoint Bypasses IP Validation

CVSS Score
4.1
EPSS Score
0.0%
EPSS Percentile
0th

Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the `/api/_action/media/external-link` endpoint allows authenticated admin users to make server-side HTTP HEAD requests to arbitrary internal IP addresses. While the parallel `uploadFromURL` flow validates target IPs against private/reserved ranges via `FileUrlValidator`, the `linkURL` flow only performs a URL format check (regex for `http://` or `https://` prefix), allowing SSRF to internal network services and cloud metadata endpoints. This issue is fixed in versions 6.6.10.18 and 6.7.10.1.

CWE CWE-918
Vendor shopware
Product shopware
Published Jul 23, 2026
Last Updated Jul 23, 2026
Stay Ahead of the Next One

Get instant alerts for shopware shopware

Be the first to know when new medium vulnerabilities affecting shopware shopware are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

shopware / shopware
< 6.6.10.18 >= 6.7.0.0, < 6.7.10.1
shopware / platform
< 6.6.10.18 >= 6.7.0.0, < 6.7.10.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/shopware/shopware/security/advisories/GHSA-gq96-5pfx-f4vc github.com: https://github.com/shopware/shopware/releases/tag/v6.6.10.18 github.com: https://github.com/shopware/shopware/releases/tag/v6.7.10.1