Back to overview

CVE-2026-39087

CRITICAL
9.8
CVSS 3.1
Description
ntfy before 2.22.0 allows SSRF because of an unanchored regular expression for web push endpoint URLs.

Metadata

CVE ID
CVE-2026-39087
State
PUBLISHED
Assigner
mitre
Reserved
2026-04-06 00:00 UTC
Published
2026-04-23 00:00 UTC
Last updated
2026-07-05 16:16 UTC
Primary CWE
CWE-777
CWE-777 Regular Expression without Anchors
Vendor / Product
ntfy / ntfy
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
ntfy ntfy 0 < 2.22.0
Weakness (CWE)
CWESourceDescription
CWE-777 cna CWE-777 Regular Expression without Anchors
CWE-94 adp CWE-94 Improper Control of Generation of Code ('Code Injection')
CVSS scores (2)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 adp CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
6.4 MEDIUM 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Back to overview