CVE-2026-48013
Shopware: SSRF in Media External-Link Endpoint Bypasses IP Validation
CVSS Score
4.1
EPSS Score
0.0%
EPSS Percentile
0th
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the `/api/_action/media/external-link` endpoint allows authenticated admin users to make server-side HTTP HEAD requests to arbitrary internal IP addresses. While the parallel `uploadFromURL` flow validates target IPs against private/reserved ranges via `FileUrlValidator`, the `linkURL` flow only performs a URL format check (regex for `http://` or `https://` prefix), allowing SSRF to internal network services and cloud metadata endpoints. This issue is fixed in versions 6.6.10.18 and 6.7.10.1.
| CWE | CWE-918 |
| Vendor | shopware |
| Product | shopware |
| Published | Jul 23, 2026 |
| Last Updated | Jul 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for shopware shopware
Be the first to know when new medium vulnerabilities affecting shopware shopware are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
None
Availability
None
Affected Versions
shopware / shopware
< 6.6.10.18 >= 6.7.0.0, < 6.7.10.1
shopware / platform
< 6.6.10.18 >= 6.7.0.0, < 6.7.10.1