CVE-2026-39087
ntfy before 2.22.0 allows SSRF because of an unanchored regular expression.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- EPSS probability
- 0.27%
- CWE
- CWE-777
- Published
- 2026-04-23
- Last modified
- 2026-07-05
Affected products
- n/a n/a
- ntfy ntfy
Weakness type
Related vulnerabilities
- CVE-2026-22068 — Apache Traffic Server: Regex mappings match with malicious domain names
- CVE-2026-56021 — Webmin information disclosure via regex pattern
- CVE-2026-40110 — jupyter-server CORS origin validation bypass via unanchored regex in allow_origin_pat